expo / expo/code-signing-certificates

VRF#26-03-KMYLK node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations

Open
#19 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
21
Forks
16
PR merge metrics
No merged PRs in 30d

Description

Greetings,

We have received a report that indicates that one of your products contains a vulnerability. To facilitate a coordinated effort in addressing and disclosing this vulnerability, we invite you to participate in the ongoing case discussion. You can access detailed information about the case and contribute to the conversation by visiting https://kb.cert.org/vince/ and creating an account on the VINCE coordination platform.

Please retain the VRF# in the subject of any email you send to us regarding this vulnerability case.

Regards,

Vulnerability Analysis Team
CERT Coordination Center
kb.cert.org / cert@cert.org

If you have any concerns about the legitimacy of this notification, please contact the CERT/CC at cert@cert.org, include the case number starting with VU# in the subject, and ask to be put in contact with the CERT/CC Coordinated Vulnerability Disclosure (CVD) Team.

https://www.kb.cert.org/vuls/guidance/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the linked CERT/CC VINCE case using the VRF#26-03-KMYLK identifier; the issue provides no repository file, entry point, reproduction, or test. Determine the affected node-forge RSA-PKCS and ED25519 implementations from the case details, then establish the remediation and validation steps through coordinated disclosure.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.