HIGH
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter
Published Sep 30, 2025
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.
Affected products
No data.
- 4.1.0
No data.
No Red Hat product state for this CVE.
financejs
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | financejs | 0 | not fixed |
Remediation
No remediation recorded yet.
References (7)
- http://financejs.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-31750 Advisory
- https://github.com/advisories/GHSA-f8r4-mf27-rf7m Advisory
- https://github.com/ebradyjobory/finance.js Product
- https://medium.com/@nakah_/cve-2025-56571-and-cve-2025-56572-denial-of-service-vulnerabilities-in-finance-js-78f8b399f53b Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-56571
- https://raw.githack.com/ebradyjobory/finance.js/6d571ea2a86d08491ceb584e292e9b76b0a60636/finance.js Product
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 30, 2025
Updated Jul 5, 2026
Reserved Aug 17, 2025
Link CVE-2025-56571
CISA Vulnrichment
Updated Oct 3, 2025
ENISA EUVD
EUVD-2025-31750 GHSA-F8R4-MF27-RF7M Assigner mitre
Published Sep 30, 2025
Updated Jul 5, 2026
Exploited since n/a
Link EUVD-2025-31750