CVE-2026-33894
Red Hat Security Advisory: Cluster Observability Operator 1.5.0
Description
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery. This issue is similar to CVE-2022-24771, but adds bytes in an addition field within the ASN structure, rather than outside of it. Additionally, forge does not validate that signatures include a minimum of 8 bytes of padding as defined by the specification, providing attackers additional space to construct Bleichenbacher forgeries. Version 1.4.0 patches the issue.
Metrics
Weakness classes (CWE)
CWE-347Base
Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
cwe.mitre.org →CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-10 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/33xxx/CVE-2026-33894.json">CVE-2026-33894</a>
- CVE Modified2026-08-31 13:17 UTC· security-advisories@github.com
- Reference: https://datatracker.ietf.org/doc/html/rfc2313#section-8
- Reference: https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
- Reference: https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
- Reference: https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp
- CVE Modified2026-08-31 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/33xxx/CVE-2026-33894.json">CVE-2026-33894</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:13826
- Reference: https://access.redhat.com/errata/RHSA-2026:19375
- Reference: https://access.redhat.com/errata/RHSA-2026:21017
- CVE Modified2026-07-20 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Cluster Observability Operator 1.5.0 (+30) → Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Cluster Observability Operator 1.5.0 (+30)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
digitalbazaar
forge1.3.3
digitalbazaar
forge1.4.0
go
golang.org/x/net
go
golang.org/x/oauth2
go
stdlib1.24.0-0
golang
go1.26.0 – 1.26.3
golang
go1.25.10
golang
http20.53.0
golang
net0.55.0
handlebarsjs
handlebars4.0.0 – 4.7.9
immutable-js
immutable3.0.0 – 3.8.3
immutable-js
immutable4.0.0 – 4.3.7
immutable-js
immutable5.0.0 – 5.1.5
References & sources
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-cfm4-qjh2-4765web
- https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwpweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-33894advisory
- https://datatracker.ietf.org/doc/html/rfc2313#section-8web
- https://github.com/digitalbazaar/forgepackage
- https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QEweb
- https://www.rfc-editor.org/rfc/rfc8017.htmlweb
- https://access.redhat.com/security/cve/CVE-2026-33894vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2452464issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33894.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:24761vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34342vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:9742vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:13826vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22629vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:21017vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24853vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19375vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22465vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:22840vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9277
A flaw was found in the shell-quote component.
criticalCVSSv3 8.1 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-6322
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-6321
A flaw was found in fast-uri.
highCVSSv3 7.5 - CVE-2026-48779
A flaw was found in ws, an open source WebSocket client and server.
highCVSSv3 7.5 - CVE-2026-4867
A flaw was found in path-to-regexp.
highCVSSv3 7.5 - CVE-2026-4800
A flaw was found in lodash.
criticalCVSSv3 9.8 - CVE-2026-42506
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1 - CVE-2026-39821
A flaw was found in golang.org/x/net/idna.
criticalCVSSv3 9.6 - CVE-2026-33941
A flaw was found in Handlebars.
highCVSSv3 8.3 - CVE-2026-33940
A flaw was found in Handlebars.js.
highCVSSv3 8.1 - CVE-2026-33939
A flaw was found in Handlebars.js.
highCVSSv3 7.5 - CVE-2026-33938
A flaw was found in Handlebars.
highCVSSv3 8.1 - CVE-2026-33937
A flaw was found in Handlebars.
criticalCVSSv3 9.8 - CVE-2026-33896
A flaw was found in Forge (also known as node-forge), a JavaScript implementation of Transport Layer Security (TLS).
criticalCVSSv3 9.1 - CVE-2026-33895
A flaw was found in Forge (also called `node-forge`), a JavaScript library used for Transport Layer Security (TLS).
highCVSSv3 7.5 - CVE-2026-33891
A flaw was found in the node-forge library, a JavaScript implementation of Transport Layer Security.
highCVSSv3 7.5 - CVE-2026-33814
A flaw was found in the HTTP/2 protocol implementation within the Go standard library (golang.org/x/net and net/http/internal/http2).
highCVSSv3 7.5 - CVE-2026-33671
A flaw was found in Picomatch, a JavaScript glob matcher.
highCVSSv3 7.5 - CVE-2026-33228
A flaw was found in flatted, a JavaScript Object Notation (JSON) parser designed for handling circular data structures.
criticalCVSSv3 9.8 - CVE-2026-32141
A denial of service flaw has been discovered in the flatted npm library.
highCVSSv3 7.5 - CVE-2026-29063
A flaw was found in Immutable.js, a library for persistent immutable data structures.
criticalCVSSv3 9.8 - CVE-2026-25681
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.1
Show 16 more CVEs
- CVE-2026-25680
A flaw was found in golang.org/x/net/html.
mediumCVSSv3 6.5 - CVE-2026-2229
A flaw was found in the undici WebSocket client.
highCVSSv3 7.5 - CVE-2026-1528
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-1526
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-12143
A flaw was found in form-data, a library for creating readable multipart/form-data streams.
highCVSSv3 7.5 - CVE-2025-58190
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of…
— - CVE-2025-47911
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denia…
— - CVE-2025-22872
A flaw was found in the HTML tokenizer component.
— - CVE-2025-22870
A flaw was found in proxy host matching.
— - CVE-2025-22868
A flaw was found in the `golang.org/x/oauth2/jws` package in the token parsing component.
— - CVE-2024-52011
A flaw was found in launch-editor, a tool that allows users to open files with line numbers in an editor from Node.js.
highCVSSv3 8.3 - CVE-2024-45338
A flaw was found in golang.org/x/net/html.
— - CVE-2024-4068
A flaw was found in the NPM package `braces.` It fails to limit the number of characters it can handle, which could lead to memory exhaus…
highCVSSv3 7.5 - CVE-2021-33623
A flaw was found in nodejs-trim-newlines.
— - CVE-2020-7753
A flaw was found in the npm library trim where a specifically crafted input can cause a regular expression to take an abnormal amount of…
highCVSSv3 7.5