Jsrsasign Project Jsrsasign — CVE-2026-4601 (Critical)
Critical vendor advisory
CVE-2026-4601
Summary
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 8.7) in Jsrsasign Project Jsrsasign. Patch or mitigate promptly.
Operator check
Review CVE-2026-4601 in your asset inventory. Apply patches per vendor guidance and verify Jsrsasign is not exposed. CVSS score: 8.7.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.