CVE-2026-4598: Infinite loop in jsrsasign
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).
AI Analysis
Technical Summary
The Red Hat Migration Toolkit for Virtualization (MTV) RHEL9 images are affected by multiple security vulnerabilities, including CVE-2026-29063, a Prototype Pollution vulnerability in the Immutable.js library. This flaw allows an attacker with low privileges to inject unwanted properties into core JavaScript object prototypes via specific API calls, such as mergeDeep() and Map.toJS(), potentially enabling arbitrary code execution or denial of service. Exploitation requires the attacker to supply crafted data to affected functions, typically necessitating some level of access to the affected application. Red Hat's advisory RHSA-2026:19410 covers these issues and advises applying all relevant previously released errata before updating. The advisory does not provide explicit patch links but indicates updated images are available. The affected components include various MTV container images for RHEL9. No active exploitation has been observed.
Potential Impact
Successful exploitation of these vulnerabilities could allow an attacker with some level of privileges to execute arbitrary code or cause denial of service by manipulating JavaScript object prototypes within the MTV RHEL9 images. This could compromise the integrity and availability of the affected systems. However, exploitation requires the attacker to be able to provide arbitrary data to the vulnerable functions, implying some degree of access to the affected environment. No known exploits in the wild have been reported, reducing immediate risk.
Mitigation Recommendations
Red Hat has released updated MTV RHEL9 images addressing these vulnerabilities as part of advisory RHSA-2026:19410. Users should ensure all previously released errata relevant to their systems are applied before updating to the latest images. Since no explicit patch links are provided, users should follow Red Hat's official documentation and update procedures for the Migration Toolkit for Virtualization version 2.9. Monitoring Red Hat's security advisories for further updates is recommended. No additional mitigations are specified in the advisory.
CVE-2026-4598: Infinite loop in jsrsasign
Description
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Red Hat Migration Toolkit for Virtualization (MTV) RHEL9 images are affected by multiple security vulnerabilities, including CVE-2026-29063, a Prototype Pollution vulnerability in the Immutable.js library. This flaw allows an attacker with low privileges to inject unwanted properties into core JavaScript object prototypes via specific API calls, such as mergeDeep() and Map.toJS(), potentially enabling arbitrary code execution or denial of service. Exploitation requires the attacker to supply crafted data to affected functions, typically necessitating some level of access to the affected application. Red Hat's advisory RHSA-2026:19410 covers these issues and advises applying all relevant previously released errata before updating. The advisory does not provide explicit patch links but indicates updated images are available. The affected components include various MTV container images for RHEL9. No active exploitation has been observed.
Potential Impact
Successful exploitation of these vulnerabilities could allow an attacker with some level of privileges to execute arbitrary code or cause denial of service by manipulating JavaScript object prototypes within the MTV RHEL9 images. This could compromise the integrity and availability of the affected systems. However, exploitation requires the attacker to be able to provide arbitrary data to the vulnerable functions, implying some degree of access to the affected environment. No known exploits in the wild have been reported, reducing immediate risk.
Mitigation Recommendations
Red Hat has released updated MTV RHEL9 images addressing these vulnerabilities as part of advisory RHSA-2026:19410. Users should ensure all previously released errata relevant to their systems are applied before updating to the latest images. Since no explicit patch links are provided, users should follow Red Hat's official documentation and update procedures for the Migration Toolkit for Virtualization version 2.9. Monitoring Red Hat's security advisories for further updates is recommended. No additional mitigations are specified in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:19410
- Cve Count
- 8
- Additional Cves
- ["CVE-2026-4599","CVE-2026-4600","CVE-2026-4601","CVE-2026-4602","CVE-2026-4800","CVE-2026-4926","CVE-2026-29063"]
- State
- PUBLISHED
Threat ID: 6a160974e29bf47b5063d48c
Added to database: 05/26/2026, 20:58:28 UTC
Last enriched: 08/10/2026, 20:19:15 UTC
Last updated: 09/13/2026, 22:01:34 UTC
Views: 160
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.