CVE-2026-4598Disclosure(kjur / jsrsasign)

LOWCVSS 7.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835CWE-1287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsrsasign

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
jsrsasign

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Technical Details · 2026-03-23: 203-23
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4598 Infinite Loop Vulnerability in jsrsasign Package Before 11.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4598

    Post summary

    A new infinite-loop vulnerability (CVE-2026-4598) has been disclosed for jsrsasign packages older than version 11.1.1, with a link provided to a vulnerability details page.

    0001056
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4598 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4598 #CVE-2026-4598 #CVE #High  #CyberSecurity #InfoSec https://t.co/phUXsijVzR

    Post summary

    The tweet announces the discovery of CVE-2026-4598, noting its severity (7.5) and high risk level without providing additional technical or mitigation details.

    0000030
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4598 Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementat… https://www.cve.org/CVERecord?id=CVE-2026-4598

    Post summary

    CVE-2026-4598 reports an infinite loop bug in jsrsasign before v11.1.1; no PoC, exploit, patch, or active exploitation is cited.

    0000071
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkjurjsrsasign-node.js-

Explore more