GHSA-8qwj-4jxw-m8jw

Suggest an improvement
Source
https://github.com/advisories/GHSA-8qwj-4jxw-m8jw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8qwj-4jxw-m8jw/GHSA-8qwj-4jxw-m8jw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8qwj-4jxw-m8jw
Aliases
Published
2026-03-23T06:30:29Z
Modified
2026-07-21T14:00:32Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass
Details

Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

Database specific
{
    "cwe_ids":  [
        "CWE-681"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-30T19:30:01Z",
    "nvd_published_at":  "2026-03-23T06:16:22Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / jsrsasign

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8qwj-4jxw-m8jw/GHSA-8qwj-4jxw-m8jw.json"