NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1313 most downloaded on npm
JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.
Last release 6 months ago
24 Mar 2026
Ships unpredictably
gaps range from 2 weeks to 3.7 years
Some releases are documented
notes for 26 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
134 releases · first in 2013
A Denial of Service (DoS) vulnerability exists due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn librar…
BigInteger.modInverse()
BigInteger.modInverse() function (inherited from the bundled jsbn
library). When modInverse() is called with a zero value as input, the
internal Extended Euclidean Algorithm enters an unreachable exit condition,
causing the process to hang indefinitely and consume 100% CPU.basicConstraints bypass in certificate chain verification.
pki.verifyCertificateChain() does not enforce RFC 5280 basicConstraints
requirements when an intermediate certificate lacks both the
basicConstraints and keyUsage extensions. This allows any leaf
certificate (without these extensions) to act as a CA and sign other
certificates, which node-forge will accept as valid.2.5.4.65 / pseudonymjsbn 1.4. Sync partly back to original style for easier
updates every decade or so.BigInteger.modInverse to avoid an infinite loop and exit early
with zero when the target object value is <= 0. Zero may not be strictly
mathematically correct but aligns with current jsbn behavior returning zero
in other situations. The alternate of a RangeError would diverge from the
rest of the API.basicConstraints on non-leaf
certificates.One column per quarter.
[pkcs12] Make digestAlgorithm parameters optional to fix PKCS#12/PFX issues introduced in 1.3.2.
An Interpretation Conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 str…
fromDer() max recursion depth check.
asn1.maxDepth global configurable maximum depth of 256.asn1.fromDer() per-call maxDepth option.maxDepth parameter has not been exposed up through
all of the API stack due to the complexities involved. Please file an issue
if there are use cases that require this instead of changing the default
maximum.2**32 - 1.2**53 - 1 .RFC 3447 and RFC 8017 allow for optional DigestAlgorithm NULL parameters for sha* algorithms and require NULL parameters for md2 and md5 algorithms.
DigestAlgorithm NULL parameters
for sha* algorithms and require NULL parameters for md2 and md5
algorithms.Three RSA PKCS#1 v1.5 signature verification issues were reported by Moosa Yahyazadeh (moosa-yahyazadeh@uiowa.edu).
digestAlgorithm structure can lead to
signature forgery.
DigestInfo ASN.1 structure. This can allow padding bytes to be removed
and garbage data added to forge a signature when a low public exponent is
being used. For more information, please see "Bleichenbacher's RSA
signature forgery based on implementation
error"
by Hal Finney.DigestInfo is not properly checked for proper ASN.1 structure. This can
lead to successful verification with signatures that contain invalid
structures but a valid digest.fromDer is now more strict and will default to ensuring all input
bytes are parsed or throw an error. A new option parseAllBytes can disable
this behavior.
RSASSA-PKCS-v1_5 DigestInfo data. Additionally check that the hash
algorithm identifier is a known value from RFC 8017
PKCS1-v1-5DigestAlgorithms. An invalid DigestInfo or algorithm identifier
will now throw an error.
1.2.840.113549.2.2 / md22.16.840.1.101.3.4.2.4 / sha2242.16.840.1.101.3.4.2.5 / sha512-2242.16.840.1.101.3.4.2.6 / sha512-256[tests]: Load entire module to improve top-level testing and coverage reporting.
URLSearchParams.[oid,x509]: Added OID 1.3.14.3.2.29 / sha1WithRSASignature for sha1 with RSA. Considered a deprecated equivalent to 1.2.840.113549.1.1.5 / sha1WithRSA…
1.3.14.3.2.29 / sha1WithRSASignature for sha1 with
RSA. Considered a deprecated equivalent to 1.2.840.113549.1.1.5 / sha1WithRSAEncryption. See discussion and
links.[x509]: Correctly compute certificate issuer and subject hashes to match behavior of openssl.
This project is over a decade old! Time for a 1.0.0 release.
forge.debug API. The API has the
potential for prototype pollution. This API was only briefly used by the
maintainers for internal project debug purposes and was never intended to be
used with untrusted user inputs. This API was not documented or advertised
and is being removed rather than fixed.forge.util.parseUrl() (and
forge.http.parseUrl alias) and use the WHATWG URL
Standard. URL is supported by modern
browsers and modern Node.js. This change is needed to address URL parsing
security issues. If forge.util.parseUrl() is used directly or through
forge.xhr or forge.http APIs, and support is needed for environments
without URL support, then a polyfill must be used.forge.task API. This API was never used, documented,
or advertised by the maintainers. If anyone was using this API and wishes to
continue development it in other project, please let the maintainers know.
Due to use in the test suite, a modified version is located in
tests/support/.forge.util.makeLink, forge.util.makeRequest,
forge.util.parseFragment, forge.util.getQueryVariables. Replace with
URL, URLSearchParams, and custom code as needed.master branch to main.v. Other tools, scripts, or scanners may need to adapt.surname, title, and givenName.serialName to serialNumber.
Depending on how applications used this id to name association it could cause
compatibility issues.BREAKING: Node.js 4 no longer supported. The code *may* still work, and non-invasive patches to keep it working will be considered. However, more mode
util.getPath, util.setPath, and util.deletePath.
util.setPath had a potential prototype pollution security issue when used
with unsafe inputs. These functions are not used by forge itself. They date
from an early time when forge was targeted at providing general helper
functions. The library direction changed to be more focused on cryptography.
Many other excellent libraries are more suitable for general utilities. If
you need a replacement for these functions, consider get, set, and unset
from lodash. But also consider the potential similar
security issues with those APIs.https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7720
util.setPath security note to function docs and to README.util.setPath function has the potential to cause
prototype pollution if used with unsafe input.
forge.util.getPath and util.setPath.
Consider get and set from lodash if you need
replacements. But also consider the potential similar security issues with
those APIs.Ensure DES-CBC given IV is long enough for block size.
Add ed25519.publicKeyFromAsn1 and ed25519.privateKeyFromAsn1 APIs.
### Fixed - Remove use of const.
const.Replace all instances of Node.js new Buffer with Buffer.from and Buffer.alloc.
new Buffer with Buffer.from and Buffer.alloc.Use basic character set for code.
Fix tag calculation when continuing an AES-GCM block.
Fix off-by-1 bug with kem random generation.
PhantomJS is deprecated, now using Headless Chrome with Karma.
notBefore and notAfter dates less
than Jan 1, 1950 or greater than or equal to Jan 1, 2050.pki.verifyCertificateChain:
validityCheckDate option to allow checking the certificate validity
period against an arbitrary Date or null for no check at all. The
current date is used by default.tls.createConnection:
verifyOptions option that passes through to
pki.verifyCertificateChain. Can be used for the above validityCheckDate
option.rsa.generateKeyPair:
crypto.generateKeyPair/crypto.generateKeyPairSync on Node.js if
available (10.12.0+) and not in pure JS mode.rsa.generateKeyPair if prng option specified since
this isn't supported by current native APIs.pki.verifyCertificateChain:
(caStore, chain, options). Older (caStore, chain, verify) signature is still supported. New style is to to pass in a
verify option.Support for PKCS#7 detached signatures.
### Fixed - Remove use of const.
const.Potential regex denial of service in form.js.
Re-publish with npm 5.6.0 due to file timestamp issues.
Support verification of SHA-384 certificates.
1.2.840.10040.4.3'/dsa-with-sha1 OID.asn1.equals loop bug.Fix digestLength for hashes based on SHA-512.
Fix test looping bugs so all tests are run.
toDer(). More tests.asn1.prettyPrint() BIT STRING display.npm run build:
.js, .min.js, and basic sourcemaps.forge.js.forge.all.js.prime.worker.js.forge.options field.forge.options.usePureJavaScript flag.forge.util.isNodejs flag (used to select "native" APIs).md.all.js which includes all digest algorithms.equals() and copy().validate() capture options for BIT STRING contents and value.forge({...}) to create new instances.forge.options.usePureJavaScript.forge/js/pki you should either
switch to just using the main forge and access forge.pki or update to
forge/lib/pki.forge/js/pki you should switch to
just using forge and access forge.pki. The bower release bundles
everything in one minified file./bower_components/forge/js/prime.worker.js will need to change to
/bower_components/forge/dist/prime.worker.min.js.md.all.js file to include all
digest algorithms. Individual files limit what they include by default to
allow smaller custom builds. For instance, pbdkf2.js has a sha1 default
but does not include any algorithm files by default. This allows the
possibility to include only sha256 without the overhead of sha1 and
sha512.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →