CVE-2025-56571: High severity Finance.js Finance.js vulnerability
Published Sep 30, 2025
·Updated
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.
Affected Software
3 affected components
Finance.js Finance.js
npm/financejs<=4.1.0
Ebradyjobory Finance.js=4.1.0
Event History
Sep 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56571?
CVE-2025-56571 is classified as a Denial of Service (DoS) vulnerability.
2
How do I fix CVE-2025-56571?
To fix CVE-2025-56571, update Finance.js to a version beyond v4.1.0.
3
Which versions of Finance.js are affected by CVE-2025-56571?
Finance.js versions up to and including v4.1.0 are affected by CVE-2025-56571.
4
What causes the vulnerability in CVE-2025-56571?
CVE-2025-56571 is caused by improper handling of the recursion/iteration limit in the IRR function's depth parameter.
5
What are the potential impacts of CVE-2025-56571?
The impacts of CVE-2025-56571 can include excessive CPU usage, leading to application stalls or crashes.