CVE-2026-4602

ADVISORY - github

Summary

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

EPSS Score: 0.00051 (0.158)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Incorrect Conversion between Numeric Types

ADVISORY - github

Incorrect Conversion between Numeric Types

ADVISORY - redhat

Incorrect Conversion between Numeric Types


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in