jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling
Published Mar 23, 2026
8.7
HIGHCVSS 4.0
EPSS 0.88%
Description
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.
Affected products
- Vendor n/a Product Jsrsasign Defaultn/a
- Version 0StatusaffectedConstraints<11.1.1
- Version
- Vendor n/a Product Org.webjars.npm:jsrsasign Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Jsrsasign | n/a |
| ||||||
| n/a | Org.webjars.npm:jsrsasign | n/a |
|
No data.
Migration Toolkit for Virtualization 2.1
migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872
Fixed · RHSA-2026:19409
Migration Toolkit for Virtualization 2.9
migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462
Fixed · RHSA-2026:19410
Red Hat Quay 3.10
quay/quay-rhel8:1775169155
Fixed · RHSA-2026:6912
Red Hat Quay 3.12
quay/quay-rhel8:1775253092
Fixed · RHSA-2026:6720
Red Hat Quay 3.15
quay/quay-rhel8:1775169219
Fixed · RHSA-2026:6568
Red Hat Quay 3.16
quay/quay-rhel9:1779204086
Fixed · RHSA-2026:19375
Red Hat Quay 3.9
quay/quay-rhel8:1775169218
Fixed · RHSA-2026:6926
| Product | Package | State | Advisory |
|---|---|---|---|
| Migration Toolkit for Virtualization 2.1 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:1779139872 | Fixed | RHSA-2026:19409 |
| Migration Toolkit for Virtualization 2.9 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:1778927462 | Fixed | RHSA-2026:19410 |
| Red Hat Quay 3.10 | quay/quay-rhel8:1775169155 | Fixed | RHSA-2026:6912 |
| Red Hat Quay 3.12 | quay/quay-rhel8:1775253092 | Fixed | RHSA-2026:6720 |
| Red Hat Quay 3.15 | quay/quay-rhel8:1775169219 | Fixed | RHSA-2026:6568 |
| Red Hat Quay 3.16 | quay/quay-rhel9:1779204086 | Fixed | RHSA-2026:19375 |
| Red Hat Quay 3.9 | quay/quay-rhel8:1775169218 | Fixed | RHSA-2026:6926 |
jsrsasign
npm
Introduced 0 Fixed 11.1.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | jsrsasign | 0 | 11.1.1 |
Remediation
Red Hat statement
This is an IMPORTANT flaw. The `jsrsasign` library, as used in Red Hat products such as Migration Toolkit for Virtualization and Red Hat Quay, is vulnerable to a signature verification bypass. A remote attacker could provide a specially crafted negative exponent to the `modPow` function, leading to incorrect modular inverse computations and allowing them to bypass signature verification.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (19)
- https://access.redhat.com/errata/RHSA-2026:19375
- https://access.redhat.com/errata/RHSA-2026:19409
- https://access.redhat.com/errata/RHSA-2026:19410
- https://access.redhat.com/errata/RHSA-2026:6568
- https://access.redhat.com/errata/RHSA-2026:6720
- https://access.redhat.com/errata/RHSA-2026:6912
- https://access.redhat.com/errata/RHSA-2026:6926
- https://access.redhat.com/security/cve/CVE-2026-4602 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2450206 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14379 Advisory
- https://gist.github.com/Kr0emer/7ecd2be7d17419e4677315ef3758faf5 ExploitMitigationThird Party Advisory
- https://github.com/advisories/GHSA-8qwj-4jxw-m8jw Advisory
- https://github.com/kjur/jsrsasign/commit/5ea1c32bb2aa894b4bd29849839afe4f98728195 Patch
- https://github.com/kjur/jsrsasign/pull/650 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-4602
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4602.json
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812274
- https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15371175 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-4602
Change history (0)
No recorded changes yet.