CVE-2026-4598

HIGH

jsrsasign < 11.1.1 - Denial of Service via Infinite Loop in bnModInverse

Title source: llm
STIX 2.1

Description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).

Scores

CVSS v3 7.5
EPSS 0.0055
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1287 CWE-835
Status published
Products (6)
None/jsrsasign < 11.1.1
None/org.webjars.npm:jsrsasign
jsrsasign_project/jsrsasign < 11.1.1
kjur/jsrsasign < 11.1.1
n/a/jsrsasign < 11.1.1
npm/jsrsasign 0 - 11.1.1npm
Published Mar 23, 2026
Tracked Since Mar 23, 2026