PT-2026-27058 · Jsrsasign · Jsrsasign

·

CVE-2026-4602

·

Published

2026-03-23

·

Updated

2026-07-20

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions jsrsasign versions prior to 11.1.1
Description Incorrect Conversion between Numeric Types occurs due to the handling of negative exponents in the file ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling the modPow() function with a negative exponent.
Recommendations Update to version 11.1.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4602
GHSA-8QWJ-4JXW-M8JW

Affected Products

Jsrsasign