Back

CRITICAL

jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing

Published Mar 23, 2026

Description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

Affected products

Remediation

Red Hat statement

IMPORTANT: A flaw in the jsrsasign library allows for private key recovery due to a missing cryptographic step in the Digital Signature Algorithm (DSA) signing process. An attacker can manipulate signature generation within the KJUR.crypto.DSA.signWithMessageHash function to force specific values, enabling the recovery of the private key. This impacts Red Hat products utilizing jsrsasign, such as Migration Toolkit for Virtualization and Red Hat Quay.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Mar 23, 2026
Updated Sep 10, 2026
Reserved Mar 22, 2026
CISA Vulnrichment
Updated Mar 23, 2026
NVD
Status Modified
Modified Sep 10, 2026
Red Hat
Severity Important
Public date Mar 23, 2026
ENISA EUVD
Assigner snyk
Published Mar 23, 2026
Updated Sep 10, 2026
Exploited since n/a
EUVD-2026-14377 GHSA-W8Q8-93CX-6H7R