CVE-2026-33891
published 2026-03-27CVE-2026-33891: Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS)…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.60%
44.9th percentile
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| digitalbazaar | forge | < 1.4.0 | 1.4.0 |
| digitalbazaar | forge | <= 1.3.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
digitalbazaar forge up to 1.3.x BigInteger.modverse infinite loop (GHSA-5m6q-g25r-mvwx / Nessus ID 304091)
vuldb·2026-06-20·CVSS 7.5
CVE-2026-33891 [HIGH] digitalbazaar forge up to 1.3.x BigInteger.modverse infinite loop (GHSA-5m6q-g25r-mvwx / Nessus ID 304091)
A vulnerability, which was classified as problematic, has been found in digitalbazaar forge up to 1.3.x. This impacts the function BigInteger.modverse. Performing a manipulation results in infinite loop.
This vulnerability was named CVE-2026-33891. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
OSV
CVE-2026-33891: Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript
osv·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891: Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.
OSV
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
osv·2026-03-26
CVE-2026-33891 [HIGH] Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
## Summary
A Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU.
Affected Package
Package name: node-forge (npm: node-forge)
Repository: https://github.com/digitalbazaar/forge
Affected versions: All versions (including latest)
Affected file: lib/jsbn.js, function bnModInverse()
Root cause component: Bundled copy of the jsbn (JavaScript Big Number) library
## Vulnerability Details
GHSA
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
ghsa·2026-03-26
CVE-2026-33891 [HIGH] CWE-835 Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
## Summary
A Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU.
Affected Package
Package name: node-forge (npm: node-forge)
Repository: https://github.com/digitalbazaar/forge
Affected versions: All versions (including latest)
Affected file: lib/jsbn.js, function bnModInverse()
Root cause component: Bundled copy of the jsbn (JavaScript Big Number) library
## Vulnerability Details
Red Hat
node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
vendor_redhat·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CWE-606 node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.
A flaw was found in the node-forge library, a JavaScript implementation of Transport Layer Security. This vulnerability, inherited from the bundled jsbn library, allows a r
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33891 fbthrift: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891 fbthrift: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [fedora-all]
CVE-2026-33891 fbthrift: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2026-33891 node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891 node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
CVE-2026-33891 node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse()
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn library). When modInverse() is called with a zero value as input, the internal Extended Euclidean Algorithm enters an unreachable exit condition, causing the process to hang indefinitely and consume 100% CPU. Version 1.4.0 patches the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat Ansible Automation Platform
Bugzilla
CVE-2026-33891 cachelib: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [fedora-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891 cachelib: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [fedora-all]
CVE-2026-33891 cachelib: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2026-33891 fbthrift: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891 fbthrift: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [epel-all]
CVE-2026-33891 fbthrift: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Bugzilla
CVE-2026-33891 cachelib: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [epel-all]
bugzilla·2026-03-27·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891 cachelib: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [epel-all]
CVE-2026-33891 cachelib: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This project only ships JavaScript code as part of the website, the files are not shipped in the binary RPMs
Wiz
CVE-2026-33891 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-33891 [HIGH] CVE-2026-33891 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-33891 :
JavaScript vulnerability analysis and mitigation
node-forge
Source : NVD
## 7.5
Score
Published March 27, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
JavaScript
Grafana
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
argo-workflows-3.6
argo-workflows-3.7
Sources
NVD
Chainguard Has Fix Added at: Apr 02, 2026
npm Severity HIGH Has Fix Added at: Mar 29, 2026
MinimOS Severity HIGH Has Fix Added at: Apr 05, 2026
Red Hat 8, 9, 10 Severity HIGH No Fix Added at: Mar 29, 2026
Wolfi Has Fix Added at: Apr 02, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in yo
https://github.com/digitalbazaar/forge/commit/9bb8d67b99d17e4ebb5fd7596cd699e11f25d023https://github.com/digitalbazaar/forge/security/advisories/GHSA-5m6q-g25r-mvwxhttps://access.redhat.com/errata/RHSA-2026:13826https://access.redhat.com/errata/RHSA-2026:24761https://access.redhat.com/errata/RHSA-2026:24762https://access.redhat.com/errata/RHSA-2026:34342https://access.redhat.com/errata/RHSA-2026:9742https://access.redhat.com/security/cve/CVE-2026-33891https://bugzilla.redhat.com/show_bug.cgi?id=2452450https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33891.json
2026-03-27
Published