CVE-2026-4602
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.
वीकनेस
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.
प्रभावित प्रोडक्ट
- kjur jsrsasign
संदर्भ
- https://gist.github.com/Kr0emer/7ecd2be7d17419e4677315ef3758faf5
- https://github.com/kjur/jsrsasign/commit/5ea1c32bb2aa894b4bd29849839afe4f98728195
- https://github.com/kjur/jsrsasign/pull/650
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812274
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15371175
- https://access.redhat.com/errata/RHSA-2026:19375
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।