jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inputs
Published Mar 23, 2026
8.7
HIGHCVSS 4.0
EPSS 0.96%
Description
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).
Affected products
- Vendor n/a Product Jsrsasign Defaultn/a
- Version 0StatusaffectedConstraints<11.1.1
- Version
- Vendor n/a Product Org.webjars.npm:jsrsasign Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Jsrsasign | n/a |
| ||||||
| n/a | Org.webjars.npm:jsrsasign | n/a |
|
No data.
Migration Toolkit for Virtualization 2.1
migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872
Fixed · RHSA-2026:19409
Migration Toolkit for Virtualization 2.9
migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462
Fixed · RHSA-2026:19410
Red Hat Quay 3.10
quay/quay-rhel8:1779822261
Fixed · RHSA-2026:22840
Red Hat Quay 3.12
quay/quay-rhel8:1775253092
Fixed · RHSA-2026:6720
Red Hat Quay 3.15
quay/quay-rhel8:1775169219
Fixed · RHSA-2026:6568
Red Hat Quay 3.16
quay/quay-rhel9:1779204086
Fixed · RHSA-2026:19375
Red Hat Quay 3.9
quay/quay-rhel8:1779811473
Fixed · RHSA-2026:23361
| Product | Package | State | Advisory |
|---|---|---|---|
| Migration Toolkit for Virtualization 2.1 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872 | Fixed | RHSA-2026:19409 |
| Migration Toolkit for Virtualization 2.9 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462 | Fixed | RHSA-2026:19410 |
| Red Hat Quay 3.10 | quay/quay-rhel8:1779822261 | Fixed | RHSA-2026:22840 |
| Red Hat Quay 3.12 | quay/quay-rhel8:1775253092 | Fixed | RHSA-2026:6720 |
| Red Hat Quay 3.15 | quay/quay-rhel8:1775169219 | Fixed | RHSA-2026:6568 |
| Red Hat Quay 3.16 | quay/quay-rhel9:1779204086 | Fixed | RHSA-2026:19375 |
| Red Hat Quay 3.9 | quay/quay-rhel8:1779811473 | Fixed | RHSA-2026:23361 |
jsrsasign
npm
Introduced 0 Fixed 11.1.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jsrsasign | 0 | 11.1.1 |
Remediation
Red Hat statement
IMPORTANT: A denial of service flaw was found in jsrsasign. This vulnerability allows a remote attacker to cause a permanent denial of service by providing specially crafted zero or negative inputs to the bnModInverse function, leading to an infinite loop. This affects Red Hat Migration Toolkit for Virtualization and Red Hat Quay, which utilize the vulnerable jsrsasign component.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (19)
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:19409
- https://access.redhat.com/errata/RHSA-2026:19410
- https://access.redhat.com/errata/RHSA-2026:22840
- https://access.redhat.com/errata/RHSA-2026:23361
- https://access.redhat.com/errata/RHSA-2026:6568
- https://access.redhat.com/errata/RHSA-2026:6720
- https://access.redhat.com/security/cve/CVE-2026-4598 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2450210 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14371 Advisory
- https://gist.github.com/Kr0emer/a1bf5cd4547cc630d2dcc5e761de8264 ExploitMitigationThird Party Advisory
- https://github.com/advisories/GHSA-8g7p-jf3g-gxcp Advisory
- https://github.com/kjur/jsrsasign/commit/ca5b027240287a1e71fe63019fc4400332594323 Patch
- https://github.com/kjur/jsrsasign/pull/648 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-4598
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4598.json
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812263
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370938 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-4598
Change history (0)
No recorded changes yet.