{"id":"CVE-2026-4598","title":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…","summary":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang th…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835","CWE-1287"],"vendor":"kjur","product":"jsrsasign","affected":["jsrsasign < 11.1.1"],"patched":["jsrsasign 11.1.1"],"published":"2026-03-23","updated":"2026-09-10","sourceUpdated":"2026-09-10T13:20:20.940","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4598","references":[{"url":"https://gist.github.com/Kr0emer/a1bf5cd4547cc630d2dcc5e761de8264","label":"report@snyk.io"},{"url":"https://github.com/kjur/jsrsasign/commit/ca5b027240287a1e71fe63019fc4400332594323","label":"report@snyk.io"},{"url":"https://github.com/kjur/jsrsasign/pull/648","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812263","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370938","label":"report@snyk.io"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19409","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19410","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:22840","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:23361","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6720","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-4598","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2450210","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4598.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-4598"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4598"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-03-23T14:37:02.606788Z"},"epss":0.00547,"epssPercentile":0.44471,"ingestedAt":"2026-06-29T13:24:34.810Z","slug":"CVE-2026-4598","body":"## Overview\n\nVersions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).\n\n## Affected\n\n- `jsrsasign < 11.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jsrsasign 11.1.1`\n\n## Vendor advisories\n\n- **RHSA-2026:19409** · Red Hat · fixed in: Migration Toolkit for Virtualization 2.1 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19409)\n- **RHSA-2026:19410** · Red Hat · fixed in: Migration Toolkit for Virtualization 2.9 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19410)\n- **RHSA-2026:22840** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-06-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:22840)\n- **RHSA-2026:6720** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-04-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:6720)\n- **RHSA-2026:6568** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6568)\n- **RHSA-2026:19375** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19375)\n- **RHSA-2026:23361** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23361)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":201689,"id":"CVE-2026-4598","ts":1789399606155,"field":"exploit_available","old":"false","new":"true"},{"seq":200421,"id":"CVE-2026-4598","ts":1789397218617,"field":"exploit_available","old":"true","new":"false"},{"seq":198345,"id":"CVE-2026-4598","ts":1789391856857,"field":"exploit_available","old":"false","new":"true"},{"seq":196138,"id":"CVE-2026-4598","ts":1789383493860,"field":"exploit_available","old":"true","new":"false"},{"seq":195067,"id":"CVE-2026-4598","ts":1789380375337,"field":"exploit_available","old":"false","new":"true"},{"seq":193854,"id":"CVE-2026-4598","ts":1789378341804,"field":"exploit_available","old":"true","new":"false"},{"seq":192641,"id":"CVE-2026-4598","ts":1789376325449,"field":"exploit_available","old":"false","new":"true"},{"seq":191428,"id":"CVE-2026-4598","ts":1789373250471,"field":"exploit_available","old":"true","new":"false"},{"seq":190213,"id":"CVE-2026-4598","ts":1789369203763,"field":"exploit_available","old":"false","new":"true"},{"seq":189000,"id":"CVE-2026-4598","ts":1789368116980,"field":"exploit_available","old":"true","new":"false"},{"seq":187783,"id":"CVE-2026-4598","ts":1789365064867,"field":"exploit_available","old":"false","new":"true"},{"seq":186570,"id":"CVE-2026-4598","ts":1789363093792,"field":"exploit_available","old":"true","new":"false"},{"seq":185356,"id":"CVE-2026-4598","ts":1789361027730,"field":"exploit_available","old":"false","new":"true"},{"seq":184143,"id":"CVE-2026-4598","ts":1789358018438,"field":"exploit_available","old":"true","new":"false"},{"seq":182394,"id":"CVE-2026-4598","ts":1789354157451,"field":"exploit_available","old":"false","new":"true"},{"seq":181187,"id":"CVE-2026-4598","ts":1789352999126,"field":"exploit_available","old":"true","new":"false"},{"seq":179980,"id":"CVE-2026-4598","ts":1789350082717,"field":"exploit_available","old":"false","new":"true"},{"seq":178773,"id":"CVE-2026-4598","ts":1789347934184,"field":"exploit_available","old":"true","new":"false"},{"seq":177566,"id":"CVE-2026-4598","ts":1789346220116,"field":"exploit_available","old":"false","new":"true"},{"seq":176359,"id":"CVE-2026-4598","ts":1789342853036,"field":"exploit_available","old":"true","new":"false"},{"seq":175813,"id":"CVE-2026-4598","ts":1789338636653,"field":"exploit_available","old":"false","new":"true"},{"seq":175683,"id":"CVE-2026-4598","ts":1789338464958,"field":"exploit_available","old":"true","new":"false"},{"seq":174478,"id":"CVE-2026-4598","ts":1789334663175,"field":"exploit_available","old":"false","new":"true"},{"seq":173273,"id":"CVE-2026-4598","ts":1789333341882,"field":"exploit_available","old":"true","new":"false"},{"seq":172087,"id":"CVE-2026-4598","ts":1789330943213,"field":"exploit_available","old":"false","new":"true"},{"seq":170901,"id":"CVE-2026-4598","ts":1789328460639,"field":"exploit_available","old":"true","new":"false"},{"seq":169696,"id":"CVE-2026-4598","ts":1789326980885,"field":"exploit_available","old":"false","new":"true"},{"seq":168491,"id":"CVE-2026-4598","ts":1789323530775,"field":"exploit_available","old":"true","new":"false"},{"seq":167286,"id":"CVE-2026-4598","ts":1789319423689,"field":"exploit_available","old":"false","new":"true"},{"seq":166081,"id":"CVE-2026-4598","ts":1789318404768,"field":"exploit_available","old":"true","new":"false"},{"seq":164876,"id":"CVE-2026-4598","ts":1789315616311,"field":"exploit_available","old":"false","new":"true"},{"seq":163671,"id":"CVE-2026-4598","ts":1789313342592,"field":"exploit_available","old":"true","new":"false"},{"seq":162466,"id":"CVE-2026-4598","ts":1789311755130,"field":"exploit_available","old":"false","new":"true"},{"seq":161261,"id":"CVE-2026-4598","ts":1789308367072,"field":"exploit_available","old":"true","new":"false"},{"seq":160766,"id":"CVE-2026-4598","ts":1789304308624,"field":"exploit_available","old":"false","new":"true"},{"seq":160313,"id":"CVE-2026-4598","ts":1789303866933,"field":"exploit_available","old":"true","new":"false"},{"seq":159374,"id":"CVE-2026-4598","ts":1789300332260,"field":"exploit_available","old":"false","new":"true"},{"seq":158604,"id":"CVE-2026-4598","ts":1789299358286,"field":"exploit_available","old":"true","new":"false"},{"seq":157568,"id":"CVE-2026-4598","ts":1789296516232,"field":"exploit_available","old":"false","new":"true"},{"seq":156363,"id":"CVE-2026-4598","ts":1789294456654,"field":"exploit_available","old":"true","new":"false"},{"seq":155158,"id":"CVE-2026-4598","ts":1789292721469,"field":"exploit_available","old":"false","new":"true"},{"seq":153953,"id":"CVE-2026-4598","ts":1789289432884,"field":"exploit_available","old":"true","new":"false"},{"seq":152603,"id":"CVE-2026-4598","ts":1789281350182,"field":"exploit_available","old":"false","new":"true"},{"seq":152243,"id":"CVE-2026-4598","ts":1789280966160,"field":"exploit_available","old":"true","new":"false"},{"seq":151204,"id":"CVE-2026-4598","ts":1789277467458,"field":"exploit_available","old":"false","new":"true"},{"seq":150165,"id":"CVE-2026-4598","ts":1789275923991,"field":"exploit_available","old":"true","new":"false"},{"seq":149132,"id":"CVE-2026-4598","ts":1789273633143,"field":"exploit_available","old":"false","new":"true"},{"seq":148099,"id":"CVE-2026-4598","ts":1789270964439,"field":"exploit_available","old":"true","new":"false"},{"seq":146139,"id":"CVE-2026-4598","ts":1789269213575,"field":"exploit_available","old":"false","new":"true"},{"seq":145041,"id":"CVE-2026-4598","ts":1789266180952,"field":"exploit_available","old":"true","new":"false"}]}