logo

Popular Forge library gets fix for signature verification bypass flaw

ID: a5478b4f-11d2-5a4f-bfb7-0521c91d7d0d

STIX ID: report--a5478b4f-11d2-5a4f-bfb7-0521c91d7d0d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-11-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A high-severity vulnerability (CVE-2025-12816) was disclosed in the widely used node-forge JavaScript cryptography library: an ASN.1 validation bug can let attackers craft malformed data to bypass signature verification and other crypto-based trust decisions. The flaw was responsibly reported with a PoC, CERT-CC highlighted impacts like authentication bypass and signed-data tampering, and node-forge 1.3.2 was released to fix the issue; users are urged to upgrade promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.