jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing
Published Mar 23, 2026
9.4
CRITICALCVSS 4.0
EPSS 0.47%
Description
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.
Affected products
- Vendor n/a Product Jsrsasign Defaultn/a
- Version 0StatusaffectedConstraints<11.1.1
- Version
- Vendor n/a Product Org.webjars.npm:jsrsasign Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Jsrsasign | n/a |
| ||||||
| n/a | Org.webjars.npm:jsrsasign | n/a |
|
No data.
Migration Toolkit for Virtualization 2.1
migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872
Fixed · RHSA-2026:19409
Migration Toolkit for Virtualization 2.9
migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462
Fixed · RHSA-2026:19410
Red Hat Quay 3.10
quay/quay-rhel8:1775169155
Fixed · RHSA-2026:6912
Red Hat Quay 3.12
quay/quay-rhel8:1775253092
Fixed · RHSA-2026:6720
Red Hat Quay 3.15
quay/quay-rhel8:1775169219
Fixed · RHSA-2026:6568
Red Hat Quay 3.16
quay/quay-rhel9:1779204086
Fixed · RHSA-2026:19375
Red Hat Quay 3.9
quay/quay-rhel8:1775169218
Fixed · RHSA-2026:6926
| Product | Package | State | Advisory |
|---|---|---|---|
| Migration Toolkit for Virtualization 2.1 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872 | Fixed | RHSA-2026:19409 |
| Migration Toolkit for Virtualization 2.9 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462 | Fixed | RHSA-2026:19410 |
| Red Hat Quay 3.10 | quay/quay-rhel8:1775169155 | Fixed | RHSA-2026:6912 |
| Red Hat Quay 3.12 | quay/quay-rhel8:1775253092 | Fixed | RHSA-2026:6720 |
| Red Hat Quay 3.15 | quay/quay-rhel8:1775169219 | Fixed | RHSA-2026:6568 |
| Red Hat Quay 3.16 | quay/quay-rhel9:1779204086 | Fixed | RHSA-2026:19375 |
| Red Hat Quay 3.9 | quay/quay-rhel8:1775169218 | Fixed | RHSA-2026:6926 |
jsrsasign
npm
Introduced 0 Fixed 11.1.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jsrsasign | 0 | 11.1.1 |
Remediation
Red Hat statement
IMPORTANT: A flaw in the jsrsasign library allows for private key recovery due to a missing cryptographic step in the Digital Signature Algorithm (DSA) signing process. An attacker can manipulate signature generation within the KJUR.crypto.DSA.signWithMessageHash function to force specific values, enabling the recovery of the private key. This impacts Red Hat products utilizing jsrsasign, such as Migration Toolkit for Virtualization and Red Hat Quay.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (19)
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:19409
- https://access.redhat.com/errata/RHSA-2026:19410
- https://access.redhat.com/errata/RHSA-2026:6568
- https://access.redhat.com/errata/RHSA-2026:6720
- https://access.redhat.com/errata/RHSA-2026:6912
- https://access.redhat.com/errata/RHSA-2026:6926
- https://access.redhat.com/security/cve/CVE-2026-4601 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2450209 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14377 Advisory
- https://gist.github.com/Kr0emer/93789fe6efe5519db9692d4ad1dad586 ExploitMitigationThird Party Advisory
- https://github.com/advisories/GHSA-w8q8-93cx-6h7r Advisory
- https://github.com/kjur/jsrsasign/commit/0710e392ec35de697ce11e4219c988ba2b5fe0eb Patch
- https://github.com/kjur/jsrsasign/pull/645 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-4601
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4601.json
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812269
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370941 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-4601
Change history (0)
No recorded changes yet.