Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8g7p-jf3g-gxcp | jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs |
Mon, 23 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jsrsasign Project
Jsrsasign Project jsrsasign |
|
| CPEs | cpe:2.3:a:jsrsasign_project:jsrsasign:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Jsrsasign Project
Jsrsasign Project jsrsasign |
Mon, 23 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inputs | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kjur
Kjur jsrsasign |
|
| Vendors & Products |
Kjur
Kjur jsrsasign |
Mon, 23 Mar 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)). | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-03-23T14:37:09.505Z
Reserved: 2026-03-22T16:25:51.590Z
Link: CVE-2026-4598
Updated: 2026-03-23T14:37:07.011Z
Status : Analyzed
Published: 2026-03-23T06:16:21.300
Modified: 2026-03-23T16:18:04.410
Link: CVE-2026-4598
OpenCVE Enrichment
Updated: 2026-03-25T14:49:50Z
Github GHSA