{"id":"CVE-2022-24772","aliases":["GHSA-x4jg-mjrx-434g"],"url":"https://o3.security/vulnerability/CVE-2022-24772","summary":"Improper Verification of Cryptographic Signature in `node-forge`","details":"Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. This can allow padding bytes to be removed and garbage data added to forge a signature when a low public exponent is being used. The issue has been addressed in `node-forge` version 1.3.0. There are currently no known workarounds.","published":"2022-03-18T13:30:20Z","modified":"2026-08-12T03:51:29.577542845Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.01031,"percentile":0.61109,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"node-forge","fixedVersion":"1.3.0"}],"fix":{"url":"https://github.com/digitalbazaar/forge/commit/3f0b49a0573ef1bb7af7f5673c0cfebf00424df1","label":"digitalbazaar/forge@3f0b49a"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24772.json"},{"type":"ADVISORY","url":"https://github.com/digitalbazaar/forge/security/advisories/GHSA-x4jg-mjrx-434g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24772"},{"type":"FIX","url":"https://github.com/digitalbazaar/forge/commit/3f0b49a0573ef1bb7af7f5673c0cfebf00424df1"},{"type":"FIX","url":"https://github.com/digitalbazaar/forge/commit/bb822c02df0b61211836472e29b9790cc541cdb2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.577542845Z"}}