An open index of dependabot pull requests across open source projects.

node-forge

Ecosystem:
npm
Package URL:
pkg:npm/node-forge
Total PRs:
5,677 Dependabot PRs
Latest PR:
about 23 hours ago
Unique Repositories:
4,621 repositories
Unique Repos (30 days):
127 repositories
Security Advisories
Improper Verification of Cryptographic Signature in node-forge
GHSA-cfm4-qjh2-4765 CVE-2022-24771 HIGH published about 4 years ago • updated 3 days ago
### Impact RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure t...
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
GHSA-5gfm-wpxj-wjgq CVE-2025-12816 HIGH published 6 months ago • updated 9 days ago
### Summary CVE-2025-12816 has been reserved by CERT/CC **Description** An Interpretation Conflict (CWE-436) vulnerability in node-forge versions...
Improper Verification of Cryptographic Signature in node-forge
GHSA-x4jg-mjrx-434g CVE-2022-24772 HIGH published about 4 years ago • updated 13 days ago
### Impact RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. Thi...
Forge has signature forgery in Ed25519 due to missing S > L check
GHSA-q67f-28xg-22rw CVE-2026-33895 HIGH published 2 months ago • updated 1 day ago
## Summary Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L...
node-forge has ASN.1 Unbounded Recursion
GHSA-554w-wpv2-vw27 CVE-2025-66031 HIGH published 6 months ago • updated 20 days ago
### Summary An Uncontrolled Recursion (CWE-674) vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to ...
Recent PRs
Package Details
Name: node-forge
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/node-forge
JSON API: View JSON
Security Advisories

15

Active advisories
HIGH 9
MODERATE 3
LOW 3
View All npm Advisories
Package Information
Description:

JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.

Repository: https://github.com/digitalbazaar/forge
Homepage: https://github.com/digitalbazaar/forge
Latest Release: 1.3.1
about 4 years ago
Dependent Repos: 3,039,204
Dependent Packages: 2,329
Downloads: 99,242,131
Ranking: Top 0.0058% by dependent repos Top 0.0211% by downloads Top 0.0344% by dependent pkgs
PR Status
Open 2,958 (52.1%)
Merged 58 (1.0%)
Closed 2,637 (46.5%)
PR Types
Major 1,165 (20.5%)
Minor 1,513 (26.7%)
Patch 2,923 (51.5%)
Removal 42 (0.7%)