{"id":"CVE-2026-4602","title":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js","summary":"Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and brea…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-681"],"vendor":"kjur","product":"jsrsasign","affected":["jsrsasign < 11.1.1"],"patched":["jsrsasign 11.1.1"],"published":"2026-03-23","updated":"2026-09-10","sourceUpdated":"2026-09-10T13:20:22.877","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-4602","references":[{"url":"https://gist.github.com/Kr0emer/7ecd2be7d17419e4677315ef3758faf5","label":"report@snyk.io"},{"url":"https://github.com/kjur/jsrsasign/commit/5ea1c32bb2aa894b4bd29849839afe4f98728195","label":"report@snyk.io"},{"url":"https://github.com/kjur/jsrsasign/pull/650","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812274","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15371175","label":"report@snyk.io"},{"url":"https://access.redhat.com/errata/RHSA-2026:19375","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19409","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:19410","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6568","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6720","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6912","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:6926","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-4602","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2450206","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4602.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-4602"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4602"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-03-23T14:37:35.060950Z"},"epss":0.0049,"epssPercentile":0.41229,"ingestedAt":"2026-06-29T13:24:34.812Z","slug":"CVE-2026-4602","body":"## Overview\n\nVersions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.\n\n## Affected\n\n- `jsrsasign < 11.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `jsrsasign 11.1.1`\n\n## Vendor advisories\n\n- **RHSA-2026:19409** · Red Hat · fixed in: Migration Toolkit for Virtualization 2.1 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19409)\n- **RHSA-2026:19410** · Red Hat · fixed in: Migration Toolkit for Virtualization 2.9 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19410)\n- **RHSA-2026:6912** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-04-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:6912)\n- **RHSA-2026:6720** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-04-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:6720)\n- **RHSA-2026:6568** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-04-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:6568)\n- **RHSA-2026:19375** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19375)\n- **RHSA-2026:6926** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-04-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:6926)","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":201691,"id":"CVE-2026-4602","ts":1789399606201,"field":"exploit_available","old":"false","new":"true"},{"seq":200423,"id":"CVE-2026-4602","ts":1789397219693,"field":"exploit_available","old":"true","new":"false"},{"seq":198347,"id":"CVE-2026-4602","ts":1789391858072,"field":"exploit_available","old":"false","new":"true"},{"seq":196140,"id":"CVE-2026-4602","ts":1789383494756,"field":"exploit_available","old":"true","new":"false"},{"seq":195069,"id":"CVE-2026-4602","ts":1789380375381,"field":"exploit_available","old":"false","new":"true"},{"seq":193856,"id":"CVE-2026-4602","ts":1789378342728,"field":"exploit_available","old":"true","new":"false"},{"seq":192643,"id":"CVE-2026-4602","ts":1789376325511,"field":"exploit_available","old":"false","new":"true"},{"seq":191430,"id":"CVE-2026-4602","ts":1789373251426,"field":"exploit_available","old":"true","new":"false"},{"seq":190215,"id":"CVE-2026-4602","ts":1789369203818,"field":"exploit_available","old":"false","new":"true"},{"seq":189002,"id":"CVE-2026-4602","ts":1789368117940,"field":"exploit_available","old":"true","new":"false"},{"seq":187785,"id":"CVE-2026-4602","ts":1789365064920,"field":"exploit_available","old":"false","new":"true"},{"seq":186572,"id":"CVE-2026-4602","ts":1789363093891,"field":"exploit_available","old":"true","new":"false"},{"seq":185358,"id":"CVE-2026-4602","ts":1789361027775,"field":"exploit_available","old":"false","new":"true"},{"seq":184145,"id":"CVE-2026-4602","ts":1789358019363,"field":"exploit_available","old":"true","new":"false"},{"seq":182396,"id":"CVE-2026-4602","ts":1789354157498,"field":"exploit_available","old":"false","new":"true"},{"seq":181189,"id":"CVE-2026-4602","ts":1789352999225,"field":"exploit_available","old":"true","new":"false"},{"seq":179982,"id":"CVE-2026-4602","ts":1789350082764,"field":"exploit_available","old":"false","new":"true"},{"seq":178775,"id":"CVE-2026-4602","ts":1789347934286,"field":"exploit_available","old":"true","new":"false"},{"seq":177568,"id":"CVE-2026-4602","ts":1789346220175,"field":"exploit_available","old":"false","new":"true"},{"seq":176361,"id":"CVE-2026-4602","ts":1789342854030,"field":"exploit_available","old":"true","new":"false"},{"seq":175815,"id":"CVE-2026-4602","ts":1789338637686,"field":"exploit_available","old":"false","new":"true"},{"seq":175685,"id":"CVE-2026-4602","ts":1789338465058,"field":"exploit_available","old":"true","new":"false"},{"seq":174480,"id":"CVE-2026-4602","ts":1789334663220,"field":"exploit_available","old":"false","new":"true"},{"seq":173275,"id":"CVE-2026-4602","ts":1789333341929,"field":"exploit_available","old":"true","new":"false"},{"seq":172089,"id":"CVE-2026-4602","ts":1789330943257,"field":"exploit_available","old":"false","new":"true"},{"seq":170903,"id":"CVE-2026-4602","ts":1789328461539,"field":"exploit_available","old":"true","new":"false"},{"seq":169698,"id":"CVE-2026-4602","ts":1789326980929,"field":"exploit_available","old":"false","new":"true"},{"seq":168493,"id":"CVE-2026-4602","ts":1789323530875,"field":"exploit_available","old":"true","new":"false"},{"seq":167288,"id":"CVE-2026-4602","ts":1789319423734,"field":"exploit_available","old":"false","new":"true"},{"seq":166083,"id":"CVE-2026-4602","ts":1789318405772,"field":"exploit_available","old":"true","new":"false"},{"seq":164878,"id":"CVE-2026-4602","ts":1789315616355,"field":"exploit_available","old":"false","new":"true"},{"seq":163673,"id":"CVE-2026-4602","ts":1789313343547,"field":"exploit_available","old":"true","new":"false"},{"seq":162468,"id":"CVE-2026-4602","ts":1789311755174,"field":"exploit_available","old":"false","new":"true"},{"seq":161263,"id":"CVE-2026-4602","ts":1789308368148,"field":"exploit_available","old":"true","new":"false"},{"seq":160768,"id":"CVE-2026-4602","ts":1789304309598,"field":"exploit_available","old":"false","new":"true"},{"seq":160315,"id":"CVE-2026-4602","ts":1789303867842,"field":"exploit_available","old":"true","new":"false"},{"seq":159376,"id":"CVE-2026-4602","ts":1789300332303,"field":"exploit_available","old":"false","new":"true"},{"seq":158606,"id":"CVE-2026-4602","ts":1789299359181,"field":"exploit_available","old":"true","new":"false"},{"seq":157570,"id":"CVE-2026-4602","ts":1789296516277,"field":"exploit_available","old":"false","new":"true"},{"seq":156365,"id":"CVE-2026-4602","ts":1789294457338,"field":"exploit_available","old":"true","new":"false"},{"seq":155160,"id":"CVE-2026-4602","ts":1789292721516,"field":"exploit_available","old":"false","new":"true"},{"seq":153955,"id":"CVE-2026-4602","ts":1789289432984,"field":"exploit_available","old":"true","new":"false"},{"seq":152605,"id":"CVE-2026-4602","ts":1789281350232,"field":"exploit_available","old":"false","new":"true"},{"seq":152245,"id":"CVE-2026-4602","ts":1789280966208,"field":"exploit_available","old":"true","new":"false"},{"seq":151206,"id":"CVE-2026-4602","ts":1789277467512,"field":"exploit_available","old":"false","new":"true"},{"seq":150167,"id":"CVE-2026-4602","ts":1789275924043,"field":"exploit_available","old":"true","new":"false"},{"seq":149134,"id":"CVE-2026-4602","ts":1789273633191,"field":"exploit_available","old":"false","new":"true"},{"seq":148101,"id":"CVE-2026-4602","ts":1789270965361,"field":"exploit_available","old":"true","new":"false"},{"seq":146141,"id":"CVE-2026-4602","ts":1789269213623,"field":"exploit_available","old":"false","new":"true"},{"seq":145043,"id":"CVE-2026-4602","ts":1789266181059,"field":"exploit_available","old":"true","new":"false"}]}