Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-33896 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificate… Forge after 1.3.3 Fix from $2,3002026-03-27 HIGH 7.5 CVE-2026-33895 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature veri… Forge after 1.3.3 Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33891 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (D… Forge after 1.3.3 Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-33894 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 sig… Forge 1.4.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2025-66031 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in nod… Forge 1.3.2+ Fix from $1,9502025-11-26 MEDIUM 5.3 CVE-2025-66030 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forg… Forge 1.3.2+ Fix from $1,6002025-11-26 HIGH 8.6 CVE-2025-12816 An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structur… Forge after 1.3.1 Fix from $1,9502025-11-25 HIGH 7.5 CVE-2022-24771 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signat… Forge 1.3.0+ Fix from $1,9502022-03-18 HIGH 7.5 CVE-2022-24772 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signat… Forge 1.3.0+ Fix from $1,9502022-03-18 MEDIUM 5.3 CVE-2022-24773 Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.3.0, RSA PKCS#1 v1.5 signat… Forge 1.3.0+ Fix from $1,6002022-03-18 MEDIUM 6.1 CVE-2022-0122 forge is vulnerable to URL Redirection to Untrusted Site Forge 1.0.0+ Fix from $1,6002022-01-06 HIGH 7.3 CVE-2020-7720 The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change re… Forge 0.10.0+ Fix from $1,9502020-09-01