CVE-2026-4602
ADVISORY - githubSummary
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.
EPSS Score: 0.00051 (0.158)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Incorrect Conversion between Numeric Types
ADVISORY - github
Incorrect Conversion between Numeric Types
ADVISORY - redhat
Incorrect Conversion between Numeric Types
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in