CVE-2026-4603 is a medium-severity division by zero vulnerability affecting jsrsasign package versions prior to 11.1.1. An attacker can exploit this locally with low complexity and privileges by providing a malformed JSON Web Key (JWK), which forces RSA public-key operations to produce deterministic zero outputs and hide "invalid key" errors. This could lead to low impacts on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, no public exploit code, and minimal community discussion or media coverage, with its EPSS score indicating a very low likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.1.1CPE matchmatch criteria | cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.