GHSA-8g7p-jf3g-gxcpHighCVSS 7.5

jsrsasign is vulnerable to DoS through Infinite Loop when processing zero or negative inputs

Published
March 23, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).

🎯 Affected products1

  • npm/jsrsasign:< 11.1.1

🔗 References (17)