CVE-2026-27452

Source
https://cve.org/CVERecord?id=CVE-2026-27452
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27452.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27452
Aliases
  • GHSA-h5rw-vxjr-8q79
Published
2026-02-21T06:50:35.877Z
Modified
2026-02-25T02:37:04.556423Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer
Details

ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27452.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/jonathanwilbur/asn1-ts

Affected ranges

Type
GIT
Repo
https://github.com/jonathanwilbur/asn1-ts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "11.0.5"
        }
    ]
}

Affected versions

0.*
0.10.3
7.*
7.0.16
v0.*
v0.10.0
v0.10.1
v0.10.2
v0.11.0
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v1.*
v1.0.0
v1.0.0-beta
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.6.1
v10.*
v10.0.0
v10.0.1
v11.*
v11.0.0
v11.0.3
v11.0.4
v11.0.5
v2.*
v2.11.0
v2.11.1
v2.11.2
v2.2.0
v2.4.0
v2.5.0
v2.5.1
v3.*
v3.1.0
v3.1.1
v3.1.1-rc1
v3.2.0
v3.2.0-rc1
v3.3.1
v5.*
v5.0.0
v7.*
v7.0.11
v7.0.12
v7.0.15
v7.0.16
v7.0.17
v7.0.18
v7.0.19
v7.0.4
v7.1.0
v7.1.1
v7.1.2
v8.*
v8.0.2
v8.0.3
v8.0.4
v8.0.5
v9.*
v9.0.0
v9.0.1
v9.0.2
v9.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27452.json"