CVE-2025-56571: n/a
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.
AI Analysis
Technical Summary
CVE-2025-56571 describes a Denial of Service vulnerability in Finance.js v4.1.0. The issue arises from the IRR function's depth parameter, which controls recursion or iteration limits. Improper handling of this parameter allows an attacker to trigger excessive CPU consumption, potentially causing the application to stall or crash. This vulnerability is categorized under CWE-834 (Excessive Iteration). There is no evidence of known exploits in the wild or available patches at this time.
Potential Impact
Successful exploitation results in a Denial of Service condition by exhausting CPU resources, causing the affected application to become unresponsive or crash. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider limiting or validating input parameters to the IRR function to prevent excessive recursion or iteration depth.
CVE-2025-56571: n/a
Description
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-56571 describes a Denial of Service vulnerability in Finance.js v4.1.0. The issue arises from the IRR function's depth parameter, which controls recursion or iteration limits. Improper handling of this parameter allows an attacker to trigger excessive CPU consumption, potentially causing the application to stall or crash. This vulnerability is categorized under CWE-834 (Excessive Iteration). There is no evidence of known exploits in the wild or available patches at this time.
Potential Impact
Successful exploitation results in a Denial of Service condition by exhausting CPU resources, causing the affected application to become unresponsive or crash. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider limiting or validating input parameters to the IRR function to prevent excessive recursion or iteration depth.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-08-17T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 68dbfb4a5fb4e84ba9305f25
Added to database: 09/30/2025, 15:46:18 UTC
Last enriched: 07/05/2026, 21:29:28 UTC
Last updated: 09/10/2026, 19:24:57 UTC
Views: 185
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.