Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4602

29
FAUCET Score

CVE-2026-4602 affects versions of the jsrsasign package prior to 11.1.1, stemming from an incorrect numeric type conversion vulnerability (CWE-681) in its ext/jsbn2.js component that mishandles negative exponents. This flaw allows an attacker to force incorrect modular inverse computations, thereby compromising cryptographic signature verification. Rated High severity with a CVSS score of 7.5 (AV:N/AC:L/A:H), this remotely exploitable vulnerability can lead to a high impact on availability by undermining the integrity of signature processes. There is currently no evidence of active exploitation, public exploit code, or significant community attention, as indicated by its absence from the KEV catalog, exploit databases, and a very low EPSS score.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.1.1CPE matchmatch criteria
cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.49%
Probability of exploitation in next 30 days
EPSS Percentile
39.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 17th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: jsrsasignFixed in: 11.1.1
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: mtv-candidate/mtv-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel9

Vendor Advisories (2)

npmGHSA-8qwj-4jxw-m8jwhigh

jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass

Mar 23, 2026
redhatCVE-2026-4602Important

jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling

Mar 23, 2026

References

access.redhat.com / errata/RHSA-2026:19375
access.redhat.com / errata/RHSA-2026:19409
access.redhat.com / errata/RHSA-2026:19410
access.redhat.com / errata/RHSA-2026:6568
access.redhat.com / errata/RHSA-2026:6720
access.redhat.com / errata/RHSA-2026:6912
access.redhat.com / errata/RHSA-2026:6926
access.redhat.com / security/cve/CVE-2026-4602
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-4602.json
gist.github.com / Kr0emer/7ecd2be7d17419e4677315ef3758faf5
ExploitMitigationThird Party Advisory
github.com / kjur/jsrsasign/commit/5ea1c32bb2aa894b4bd29849839afe4f98728195
Patch
github.com / kjur/jsrsasign/pull/650
Issue Tracking
security.snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-15812274
security.snyk.io / vuln/SNYK-JS-JSRSASIGN-15371175
Third Party Advisory