A vulnerability described as problematic has been identified in jsrsasign up to 11.1.0. The affected element is an unknown function of the file ext/jsbn2.js. Such manipulation leads to incorrect conversion between numeric types.

This vulnerability is referenced as CVE-2026-4602. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.