Junglewise Threat Intelligence

CVE-2019-9153: OpenPGP.js message signature type bypass

CVE-2019-9153 · Severity: low · CVSS 3 · Published 2019-08-23

Technologies: openpgp (npm). Vendors: npm.

Executive brief

OpenPGP.js is a JavaScript library used to implement PGP encryption and digital signatures in web applications and Node.js services. A flaw in signature verification allowed attackers to forge signed messages by reusing signature packets without proper type validation, potentially enabling message spoofing and authentication bypass in applications relying on PGP signatures.

Technical details

OpenPGP.js versions prior to 4.2.0 failed to validate that a message signature was of the correct type (text or binary). An attacker could construct arbitrary signed messages by extracting standalone or timestamp signature packets from a victim and reapplying them to different message content, bypassing signature verification. The vulnerability exists because the library did not enforce that only binary or text signature types are valid for message verification. The fix, released in version 4.2.0, adds explicit type checking to accept only binary or text signatures when verifying messages. This is a network-accessible vulnerability with no authentication requirement.

Affected products

  • OpenPGP.js openpgp <4.2.0

Timeline

  • 2019-08-23: disclosed
  • 2019-08-23: patched: Version 4.2.0 released with fix

References

Related threats