Junglewise Threat Intelligence

CVE-2025-56571: ebradyjobory Finance.js denial of service in IRR function

CVE-2025-56571 · Severity: high · CVSS 7.5 · Published 2025-09-30

Vendors: npm.

Executive brief

Finance.js, a JavaScript library used for financial calculations, contains a flaw in how it processes Internal Rate of Return (IRR) calculations. An attacker can provide a specific input that forces the library into an endless or excessive loop, consuming all available processor power. This can lead to the application becoming unresponsive or crashing, potentially disrupting financial services or web applications that rely on this library.

Technical details

A Denial of Service (DoS) vulnerability exists in Finance.js v4.1.0 within the Internal Rate of Return (IRR) function. The vulnerability is classified as CWE-834 (Excessive Iteration) and stems from improper handling of the 'depth' parameter, which controls recursion or iteration limits. A remote, unauthenticated attacker can exploit this by providing inputs that trigger excessive CPU consumption. This leads to an application hang or crash. The attack vector is network-based with low complexity and requires no user interaction.

Affected products

  • ebradyjobory finance.js 4.1.0

Timeline

  • 2025-09-30: disclosed
  • 2025-09-30: advisory

References

Related threats