Jsrsasign Project Jsrsasign — CVE-2026-4601 (Critical)

Date Mar 23, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Jsrsasign Project · Jsrsasign
CVE CVE-2026-4601
Critical vendor advisory CVE-2026-4601

Summary

Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 8.7) in Jsrsasign Project Jsrsasign. Patch or mitigate promptly.

Operator check

Review CVE-2026-4601 in your asset inventory. Apply patches per vendor guidance and verify Jsrsasign is not exposed. CVSS score: 8.7.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.