CVE-2025-56571
EUVD-2025-3175030.09.2025, 16:15
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper handling of the recursion/iteration limit can lead to excessive CPU usage, causing application stalls or crashes.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ebradyjobory | finance.js | 4.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration