Executive brief
jsrsasign is a popular JavaScript library used for cryptography, including digital signatures and certificate processing. A flaw in how the library handles specific mathematical calculations allows an attacker to trigger an infinite loop, which permanently freezes the affected application. This results in a total denial of service, potentially crashing web servers or applications that rely on this library to process security tokens or encrypted data.
Technical details
A vulnerability exists in the jsrsasign library (specifically within ext/jsbn2.js) due to an infinite loop in the BigInteger.modInverse implementation. The bnModInverse function fails to properly normalize negative inputs or handle zero as an input, causing the binary-GCD loop to never reach an exit condition. A remote, unauthenticated attacker can exploit this by providing crafted inputs to functions that utilize modular inversion, leading to 100% CPU utilization and a permanent hang of the JavaScript execution thread. The issue is fixed in version 11.1.1 by adding early return checks for zero and normalizing negative inputs using the mod(m) function.
Affected products
- kjur jsrsasign < 11.1.1
Timeline
- 2026-02-20: patched: Fix merged into master branch via PR #648
- 2026-03-23: advisory: GitHub Advisory and NVD entry published