Back

HIGH

jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling

Published Mar 23, 2026

Description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

Affected products

Remediation

Red Hat statement

This is an IMPORTANT flaw. The `jsrsasign` library, as used in Red Hat products such as Migration Toolkit for Virtualization and Red Hat Quay, is vulnerable to a signature verification bypass. A remote attacker could provide a specially crafted negative exponent to the `modPow` function, leading to incorrect modular inverse computations and allowing them to bypass signature verification.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Mar 23, 2026
Updated Sep 10, 2026
Reserved Mar 22, 2026
CISA Vulnrichment
Updated Mar 23, 2026
NVD
Status Modified
Modified Sep 10, 2026
Red Hat
Severity Important
Public date Mar 23, 2026
ENISA EUVD
Assigner snyk
Published Mar 23, 2026
Updated Sep 10, 2026
Exploited since n/a
EUVD-2026-14379 GHSA-8QWJ-4JXW-M8JW