CVE-2026-4603Disclosure(kjur / jsrsasign)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowInt reduction logic in ext/jsbn.js. An attacker can force RSA public-key operations (e.g., verify and encryption) to collapse to deterministic zero outputs and hide “invalid key” errors by supplying a JWK whose modulus decodes to zero.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-369

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jsrsasign

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
jsrsasign

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-23: 2Technical Details · 2026-03-23: 203-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4603 📊 Severity: 5.9 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4603 #CVE-2026-4603 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/Yx6KXZ7asQ

    Post summary

    The tweet announces the new CVE-2026-4603, notes its medium severity (5.9), and supplies a link to the NVD entry for further details.

    0000022
    111 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4603 Versions of the package jsrsasign before 11.1.1 are vulnerable to Division by zero due to the RSASetPublic/KEYUTIL parsing path in ext/rsa.js and the BigInteger.modPowI… https://www.cve.org/CVERecord?id=CVE-2026-4603

    Post summary

    The text announces CVE‑2026‑4603, detailing a division‑by‑zero flaw in jsrsasign <11.1.1 affecting RSASetPublic/KEYUTIL parsing and BigInteger.modPowI.

    0000081
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkjurjsrsasign-node.js-

Explore more