Package
wazuh-dashboard-security-plugin
Component
node-forge
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
node-forge 1.4.0 is affected by CVE-2026-85393, an incomplete fix for CVE-2026-33894 in RSA PKCS#1 v1.5 signature verification. 1.4.0 is the latest node-forge release and every version up to and including it is affected; upstream has not published a fixed release yet. The issue is tracked at https://github.com/digitalbazaar/forge/issues/1149. node-forge is a dependency of OpenSearch Dashboards, on which Wazuh Dashboard is built, and of the Wazuh Security Dashboards plugin, and will be updated once a fixed node-forge release is available.
Status