Popular Forge library gets fix for signature verification bypass flaw
ID: a5478b4f-11d2-5a4f-bfb7-0521c91d7d0d
STIX ID: report--a5478b4f-11d2-5a4f-bfb7-0521c91d7d0d
Feed Name: Bleeping Computer
Threat Score
A high-severity vulnerability (CVE-2025-12816) was disclosed in the widely used node-forge JavaScript cryptography library: an ASN.1 validation bug can let attackers craft malformed data to bypass signature verification and other crypto-based trust decisions. The flaw was responsibly reported with a PoC, CERT-CC highlighted impacts like authentication bypass and signed-data tampering, and node-forge 1.3.2 was released to fix the issue; users are urged to upgrade promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
