ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.
History

Tue, 03 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jonathanwilbur:asn1-ts:*:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 25 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Jonathanwilbur
Jonathanwilbur asn1-ts
Vendors & Products Jonathanwilbur
Jonathanwilbur asn1-ts

Sat, 21 Feb 2026 07:15:00 +0000

Type Values Removed Values Added
Description ASN.1 TypeScript ESM library, including codecs for Basic Encoding Rules (BER) and Distinguished Encoding Rules (DER). In versions 11.0.5 and below, in some cases, decoding an INTEGER could leak the underlying ArrayBuffer. This issue is expected to be fixed in version 11.0.6.
Title ASN.1 TypeScript Library: Decoding an INTEGER could leak the underlying ArrayBuffer
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-21T06:50:35.877Z

Updated: 2026-02-24T18:54:48.702Z

Reserved: 2026-02-19T17:25:31.100Z

Link: CVE-2026-27452

cve-icon Vulnrichment

Updated: 2026-02-24T18:54:41.271Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-21T07:16:13.210

Modified: 2026-03-03T17:28:50.777

Link: CVE-2026-27452

cve-icon Redhat

No data.