CVE 9.2 CRITICAL

ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer_CVE-2026-27452

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Description

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.

AI Analysis

Decoding an INTEGER could leak the underlying ArrayBuffer in versions 11.0.5 and below

Basic Information

ID CVE-2026-27452
Source GitHub_M
Published Feb 21, 2026 at 06:50

Affected Product

Vendor JonathanWilbur
Product asn1-ts
Version <= 11.0.5
Affected Versions JonathanWilbur asn1-ts <= 11.0.5

CWE Classification

AI Assessment

AI Score 9.2 / 10
AI Severity Critical
Vendor JonathanWilbur
Product asn1-ts
Version 11.0.5 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.