PT-2026-27059 · Jsrsasign · Jsrsasign
Kr0Emer
·
Publicado
2026-03-23
·
Atualizado
2026-03-23
·
CVE-2026-4603
CVSS v3.1
5.9
Média
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
jsrsasign versions prior to 11.1.1
Description
The jsrsasign package contains a flaw related to division by zero. This issue stems from the RSASetPublic/KEYUTIL parsing path within the 'ext/rsa.js' file and the BigInteger.modPowInt reduction logic in 'ext/jsbn.js'. An attacker can exploit this by providing a JSON Web Key (JWK) with a modulus that decodes to zero, causing RSA public-key operations, such as verification and encryption, to produce deterministic zero outputs and conceal “invalid key” errors.
Recommendations
Update jsrsasign to version 11.1.1 or later.
Exploit
Correção
Divide By Zero
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jsrsasign