Back

HIGH

jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inputs

Published Mar 23, 2026

Description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).

Affected products

Remediation

Red Hat statement

IMPORTANT: A denial of service flaw was found in jsrsasign. This vulnerability allows a remote attacker to cause a permanent denial of service by providing specially crafted zero or negative inputs to the bnModInverse function, leading to an infinite loop. This affects Red Hat Migration Toolkit for Virtualization and Red Hat Quay, which utilize the vulnerable jsrsasign component.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (2)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Mar 23, 2026
Updated Sep 10, 2026
Reserved Mar 22, 2026
CISA Vulnrichment
Updated Mar 23, 2026
NVD
Status Modified
Modified Sep 10, 2026
Red Hat
Severity Important
Public date Mar 23, 2026
ENISA EUVD
Assigner snyk
Published Mar 23, 2026
Updated Sep 10, 2026
Exploited since n/a
EUVD-2026-14371 GHSA-8G7P-JF3G-GXCP