Ebradyjobory maintains the finance.js library, a focused financial-computation component whose narrow product scope belies its potential reach across downstream applications that incorporate the library. The observed vulnerability patterns center on resource-handling weaknesses, specifically excessive iteration and uncontrolled resource consumption, which are characteristic risks in calculation-heavy or data-processing-oriented code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ebradyjobory over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56572HIGH An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter. | Sep 30, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-56571HIGH Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive | Sep 30, 2025 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ebradyjobory.
Media articles that mention a CVE ID that affects a product developed by Ebradyjobory — matched by CVE ID, not by vendor name.