CVE-2026-4602 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js.…
High CVSS: 7.7

CVE-2026-4602

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.
Vendor
Jsrsasign Project
Product
Jsrsasign
CWE
CWE-681
Yayın Tarihi
2026-03-23 06:16:22
Güncelleme
2026-03-23 16:08:58
Source Identifier
report@snyk.io
KEV Date Added
-

Kategoriler

Referanslar