Intel

AIKIDO-2026-10488

jsrsasign is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

50

Medium Risk

This Affects:

JSjsrsasign
6.1.2 - 11.1.1
Fixed in 11.1.2

TL;DR

Affected versions of this package are vulnerable to denial of service (DoS) due to an infinite loop in the ASN.1 parsing logic. The ASN1HEX.getChildIdx function processes attacker-controlled input without properly validating value lengths, which can cause the parser to enter a non-terminating loop when handling malformed ASN.1 structures. An attacker able to supply crafted input can trigger excessive CPU consumption, leading to application hang or service disruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

jsrsasign is vulnerable to Denial of Service (DoS) in versions 6.1.2 - 11.1.1.

How to fix this

Upgrade the jsrsasign library to the patch version.