Skip to content

[GHSA-q3gh-5r98-j4h3] RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign - #9705

Open
nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9705from
nikpivkin-GHSA-q3gh-5r98-j4h3
Open

nikpivkin wants to merge 1 commit into
nikpivkin/advisory-improvement-9705from
nikpivkin-GHSA-q3gh-5r98-j4h3

Conversation

@nikpivkin

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The range should end at < 8.0.17, not < 8.0.16.

The fix kjur/jsrsasign@3bcc088 is in tag 8.0.17 and not in tag 8.0.16.

So version 8.0.16 is still vulnerable but is outside the current range.

@github

github commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

Hi there @kjur! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI balanced review requested due to automatic review settings September 22, 2026 17:44
@github-actions
github-actions Bot changed the base branch from main to nikpivkin/advisory-improvement-9705 September 22, 2026 17:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The affected-version range must be retained and corrected to < 8.0.17.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates the jsrsasign advisory’s affected-version metadata for the RSA-PSS vulnerability.

Changes:

  • Updates the advisory modification timestamp.
  • Removes last_known_affected_version_range instead of correcting it to < 8.0.17.
File Description
advisories/​github-reviewed/​2020/​06/​GHSA-q3gh-5r98-j4h3/​GHSA-q3gh-5r98-j4h3.json Updates advisory metadata and affected-version information.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The advisory correction is consistent and has no unresolved issues.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants