node-forge
NPM Package
Vulnerability Check
JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.
node-forge
Advisory Breakdown
Severity Rating
High severity15 advisories
High severity
Weekly downloads
34,982,655
Total advisories
15
Latest version
1.4.0
License
(BSD-3-Clause OR GPL-2.0)
Known advisories
OSV records for the npm ecosystem
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
Improper Verification of Cryptographic Signature in `node-forge`
node-forge has ASN.1 Unbounded Recursion
node-forge has an Interpretation Conflict vulnerability via its ASN.1 Validator Desynchronization
Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
Prototype Pollution in node-forge debug API.
node-forge is vulnerable to ASN.1 OID Integer Truncation
Open Redirect in node-forge
Prototype Pollution in node-forge
Improper Verification of Cryptographic Signature in node-forge
URL parsing in node-forge could lead to undesired behavior.
Forge has signature forgery in RSA-PKCS due to ASN.1 extra field
Forge has signature forgery in Ed25519 due to missing S > L check
Prototype Pollution in node-forge util.setPath API
Improper Verification of Cryptographic Signature in node-forge
Checked Jun 6, 2026, 3:54 AM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- node-forge
- Ecosystem
- npm
- Latest version
- 1.4.0
- License
- (BSD-3-Clause OR GPL-2.0)
- Weekly downloads
- 34,982,655
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/6/2026, 3:54:05 AM