CVE-2025-56572: High severity Unknown finance.js vulnerability
Published Sep 30, 2025
·Updated
An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.
Affected Software
3 affected components
Unknown finance.js
npm/financejs<=4.1.0
Ebradyjobory Finance.js=4.1.0
Event History
Sep 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Data Sourced
via GitHub·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56572?
CVE-2025-56572 is classified as a denial of service vulnerability that can impact the performance of applications using finance.js v.4.1.0.
2
How do I fix CVE-2025-56572?
To mitigate CVE-2025-56572, upgrade to a version of finance.js that is greater than 4.1.0.
3
What versions of finance.js are affected by CVE-2025-56572?
CVE-2025-56572 affects finance.js up to and including version 4.1.0.
4
What type of attack is associated with CVE-2025-56572?
CVE-2025-56572 is associated with remote denial of service attacks via the seekZero() parameter.
5
Can CVE-2025-56572 be exploited remotely?
Yes, CVE-2025-56572 can be exploited by remote attackers to cause denial of service in applications using the vulnerable version of finance.js.