<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:14:10.387406+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-20283</id>
    <title>cnvd-2021-20283</title>
    <updated>2026-10-06T10:14:10.461461+00:00</updated>
    <content>cnvd-2021-20283</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-20283"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42573</id>
    <title>EUVD-2026-42573</title>
    <updated>2026-10-06T10:14:10.461514+00:00</updated>
    <content>EUVD-2026-42573</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42573"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14966</id>
    <title>fkie_cve-2020-14966</title>
    <updated>2026-10-06T10:14:10.461536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in the jsrsasign package through 8.0.18 for Node.js. It allows a malleability in ECDSA signatures by not checking overflows in the length of a sequence and '0' characters appended or prepended to an integer. The modified signatures are verified as valid. This could have a security-relevant impact if an application relied on a single canonical signature.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-14966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p8c3-7rj8-q963</id>
    <title>GHSA-p8c3-7rj8-q963 — ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasign</title>
    <updated>2026-10-06T10:14:10.461590+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: jsrsasign</p>
<p>### Impact
Jsrsasign supports ECDSA signature validation which signature value is represented by ASN.1 DER encoding. This vulnerablity may accept a wrong ASN.1 DER encoded ECDSA signature such as:</p>
<p>- wrong multi-byte ASN.1 length of TLV (ex. 0x820045 even though 0x45 is correct)
- prepending zeros with ASN.1 INTEGER value (ex. 0x00000123 even though 0x0123 is correct)
- appending zeros to signature of ASN.1 TLV (ex. 0x3082....1fbc000000 even though 0x3082....1fbc, appending zeros are ignored.)</p>
<p>This vulnerability was fixed by strict ASN.1 DER checking.</p>
<p>Here is an assessment of this vulnerability:</p>
<p>- If you are not use ECDSA signature validation, this vulnerability is not affected.
- Not ASN.1 format signature like just concatenation of R and S value is not affected such as Bitcoin.
- This vulnerability is affected to all ECC curve parameters.
- Risk to accept a forged or crafted message to be signed is low.
- Risk to raise memory corruption is low since jsrsasign uses BigInteger class.
- ECDSA signatures semantically the same to valid one may be accepted as valid. There are many malleable variants.</p>
<p>As discussed [here](https://crypto.stackexchange.com/questions/24862/ber-or-der-x9-62-for-ecdsa-signature), there is no standards like X9.62 which requires ASN.1 DER. So ASN.1 BER can be applied to ECDSA however most of implementations like OpenSSL do strict ASN.1 DER checking.</p>
<p>### Patches
Users using ECDSA signature validation should upgrade to 8.0.19.</p>
<p>### Workarounds
Do str…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p8c3-7rj8-q963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-14966</id>
    <title>gsd-2020-14966</title>
    <updated>2026-10-06T10:14:10.461671+00:00</updated>
    <content>gsd-2020-14966</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-14966"/>
  </entry>
</feed>
