highCVSS 7.5Vulnerability
CVE-2026-4598
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).
Properties
- summary
- jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs
- severity
- high
- epss_score
- 0.00547
- cvss_score
- 7.5
- ghsa_published
- 2026-03-23T06:30:29Z
- source_url
- https://github.com/advisories/GHSA-8g7p-jf3g-gxcp
- ghsa_updated
- 2026-03-29T15:51:29Z
- ghsa_id
- GHSA-8g7p-jf3g-gxcp
- cve_id
- CVE-2026-4598
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- false
- epss_percentile
- 0.42915
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
REPORTED_BY (1)
→[Source]GitHub Advisory Database
AFFECTS (1)
→[Software]npm/jsrsasign
HAS_WEAKNESS (1)
→[Weakness]Loop with Unreachable Exit Condition ('Infinite Loop')
Explore deeper with Ninja Signal's threat intelligence graph