Junglewise Threat Intelligence

CVE-2025-56572: ebradyjobory finance.js denial of service in seekZero

CVE-2025-56572 · Severity: high · CVSS 7.5 · Published 2025-09-30

Vendors: npm.

Executive brief

Finance.js is a JavaScript library used for financial calculations in web applications and services. A vulnerability in the seekZero() function allows remote attackers to trigger uncontrolled resource consumption, causing the application to become unresponsive or crash without requiring authentication or user interaction.

Technical details

The vulnerability is a denial of service (DoS) flaw in the seekZero() function of finance.js version 4.1.0 and earlier versions. The issue involves uncontrolled resource consumption (CWE-400/CWE-770), where specially crafted input to the seekZero() parameter can cause excessive processing. The attack is remotely exploitable over a network without requiring authentication or user interaction, making it easily accessible to attackers. Successful exploitation causes a denial of service condition, rendering the application unresponsive. No patch information is currently available in the advisory, and the vulnerability has not been observed in active exploitation in the wild at the time of publication.

Affected products

  • ebradyjobory finance.js 0 to 4.1.0

Timeline

  • 2025-09-30: disclosed: Vulnerability disclosed and published to NVD and OSV
  • 2025-09-30: other: CVSS severity assessment published as HIGH (7.5)

References

Related threats