CVE-2026-4598 is an infinite loop vulnerability affecting jsrsasign package versions before 11.1.1, specifically in the bnModInverse function when handling zero or negative inputs, which can lead to a denial of service. This vulnerability is rated High with a CVSS score of 7.5 (AV:N/AC:L/A:H), indicating it can be exploited remotely with low complexity to permanently hang affected processes. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog. Community discussion is minimal, with only two mentions identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.1.1CPE matchmatch criteria | cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.