CVE-2025-56571
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursio
CVSS
7.5
Alto
EPSS
0.4%
p33
KEV
—
Exploit Today
10
0-100
Publicado: 30 sept 2025 · Última mod.: 5 jul 2026 · CWE-834
0.4%EPSS · 30 días0.4%
2026-06-302026-07-20
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.