CVE-2026-33894

Red Hat Security Advisory: Cluster Observability Operator 1.5.0

Description

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery. This issue is similar to CVE-2022-24771, but adds bytes in an addition field within the ASN structure, rather than outside of it. Additionally, forge does not validate that signatures include a minimum of 8 bytes of padding as defined by the specification, providing attackers additional space to construct Bleichenbacher forgeries. Version 1.4.0 patches the issue.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
39.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-01 14:36 UTC
CWE-347, CWE-20

Weakness classes (CWE)

  • CWE-347Base

    Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

    cwe.mitre.org →
  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-10 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/33xxx/CVE-2026-33894.json">CVE-2026-33894</a>
  2. CVE Modified2026-08-31 13:17 UTC· security-advisories@github.com
    • Reference: https://datatracker.ietf.org/doc/html/rfc2313#section-8
    • Reference: https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
    • Reference: https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
    • Reference: https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
  3. CVE Modified2026-08-31 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/33xxx/CVE-2026-33894.json">CVE-2026-33894</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:13826
    • Reference: https://access.redhat.com/errata/RHSA-2026:19375
    • Reference: https://access.redhat.com/errata/RHSA-2026:21017
  4. CVE Modified2026-07-20 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Cluster Observability Operator 1.5.0 (+30)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Cluster Observability Operator 1.5.0 (+30)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • digitalbazaar

    forge1.3.3

  • digitalbazaar

    forge1.4.0

  • go

    golang.org/x/net

  • go

    golang.org/x/oauth2

  • go

    stdlib1.24.0-0

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    http20.53.0

  • golang

    net0.55.0

  • handlebarsjs

    handlebars4.0.0 – 4.7.9

  • immutable-js

    immutable3.0.0 – 3.8.3

  • immutable-js

    immutable4.0.0 – 4.3.7

  • immutable-js

    immutable5.0.0 – 5.1.5

References & sources

Linked CVEs

Show 16 more CVEs
IDCVE-2026-33894