CVE-2026-4598
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).
Schwachstellenklasse
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).
Betroffene Produkte
- kjur jsrsasign
Quellen
- https://gist.github.com/Kr0emer/a1bf5cd4547cc630d2dcc5e761de8264
- https://github.com/kjur/jsrsasign/commit/ca5b027240287a1e71fe63019fc4400332594323
- https://github.com/kjur/jsrsasign/pull/648
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812263
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370938
- https://access.redhat.com/errata/RHSA-2026:19375
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.