Executive brief
node-forge is a popular JavaScript cryptography library used to perform digital signature verification in applications. A flaw in RSA signature verification allows attackers to forge valid signatures by exploiting improper validation of padding bytes, compromising the integrity of any application that relies on this library to authenticate messages or code.
Technical details
The vulnerability exists in node-forge's RSA PKCS#1 v1.5 signature verification implementation, which fails to validate trailing garbage bytes after decoding a DigestInfo ASN.1 structure (CWE-347). An attacker can exploit this by removing legitimate padding and appending arbitrary data to a crafted signature. This attack is practical when a low public exponent is used, allowing signature forgery without any authentication or user interaction required. The flaw affects all versions prior to 1.3.0, which includes the fix that properly validates the structure of signed data.
Affected products
- Digital Bazaar node-forge before 1.3.0
Timeline
- 2022-03-18: disclosed
- 2022-03-18: patched: Fixed in version 1.3.0