Feed/CVE-2026-4602
CVE-2026-4602HIGHCVSS 7.5

CVE-2026-4602

Published Mar 23, 2026·Updated Aug 17, 2026

NVD Description

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

Affected Packages (1)

jsrsasignNPM
Fixed in 11.1.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free