CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4599

Critical · CVSS 9.1

jsrsasign — Incomplete Comparison with Missing Factors leading to DSA nonce bias and private key recovery

CVSS
9.1
nvd
EPSS
0.48%
39th pct
KEV
No
Class
oss containerizable
CWE-1023, CWE-338

Description

Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.

Search profile — drives PoC discovery

Symbols getRandomBigIntegerZeroToMaxgetRandomBigIntegerMinToMaxcompareTocrypto-1.1.jssrc/crypto-1.1.js
Keywords CVE-2026-4599jsrsasignDSA nonce biasprivate key recoverygetRandomBigIntegerZeroToMaxgetRandomBigIntegerMinToMaxcompareToCWE-1023SNYK-JS-JSRSASIGN-15370939jsrsasign 11.1.1jsrsasign DSA
Versions: >=7.0.0 <11.1.1

Affected packages

npm jsrsasign 7.0.0 → 11.1.1

References

Status: enriched · ingested 2026-06-22T06:00:15.000Z · profiled 2026-06-22T06:30:15.000Z