CVE-2026-4602General(kjur / jsrsasign)

LOWCVSS 7.7 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch kjur jsrsasign systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-681

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsrsasign

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
jsrsasign

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-23: 4Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 303-23
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨🔒 Critical security alert for #JavaScript devs! Older versions of *jsrsasign* (prior to 11.1.1) mishandle negative exponents, risking signature verification. Update now to safeguard your apps from forged signatures! 🔗➡️ https://www.tenable.com/cve/CVE-2026-4602 #CyberSecurity #DevSecOps

    Post summary

    The text warns about a signature forgery flaw in older jsrsasign versions and instructs users to update to 11.1.1 to fix the issue.

    0000039
    258 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4602 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4602 #CVE-2026-4602 #CVE #High  #CyberSecurity #InfoSec https://t.co/xtpo9Yj3c0

    Post summary

    The tweet merely announces CVE‑2026‑4602 with a severity rating and links to the NVD entry, providing no technical details, PoC, exploit, or remediation.

    0000030
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4602 Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An atta… https://www.cve.org/CVERecord?id=CVE-2026-4602

    Post summary

    The statement announces a vulnerability in jsrsasign (CVE-2026-4602) with technical details but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000068
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4602 Numeric Type Conversion Vulnerability in jsrsasign Before 11.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4602

    Post summary

    The post announces CVE-2026-4602, a numeric type conversion issue affecting jsrsasign before 11.1.1, and links to a vulnerability detail page but provides no additional technical, exploit, or mitigation information.

    0000043
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkjurjsrsasign-node.js-

Explore more