Vulnerability in node-forge Library Allows Signature Verification Bypass

Vulnerability in node-forge Library Allows Signature Verification Bypass

First seen 26 Nov 2025, 20:34 UTC Kb.CertBleepingcomputer 36.8

Article Content

Browse articles
ThreatCluster

A high-severity vulnerability (CVE-2025-12816) was identified in the node-forge JavaScript cryptography library, enabling attackers to bypass signature verifications by manipulating ASN.1 data structures. Users of the library are advised to update to the patched version to mitigate the risk of exploitation.