expo / expo/code-signing-certificates
VRF#26-03-KMYLK node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations
- Dominant language
- JavaScript
- Stars
- 21
- Forks
- 16
- PR merge metrics
- No merged PRs in 30d
Description
Greetings,
We have received a report that indicates that one of your products contains a vulnerability. To facilitate a coordinated effort in addressing and disclosing this vulnerability, we invite you to participate in the ongoing case discussion. You can access detailed information about the case and contribute to the conversation by visiting https://kb.cert.org/vince/ and creating an account on the VINCE coordination platform.
Please retain the VRF# in the subject of any email you send to us regarding this vulnerability case.
Regards,
Vulnerability Analysis Team
CERT Coordination Center
kb.cert.org / cert@cert.org
If you have any concerns about the legitimacy of this notification, please contact the CERT/CC at cert@cert.org, include the case number starting with VU# in the subject, and ask to be put in contact with the CERT/CC Coordinated Vulnerability Disclosure (CVD) Team.
https://www.kb.cert.org/vuls/guidance/
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the linked CERT/CC VINCE case using the VRF#26-03-KMYLK identifier; the issue provides no repository file, entry point, reproduction, or test. Determine the affected node-forge RSA-PKCS and ED25519 implementations from the case details, then establish the remediation and validation steps through coordinated disclosure.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100