CVE-2026-2739 PUBLISHED

Assigner: snyk
Reserved: 19.02.2026 Published: 20.02.2026 Updated: 20.02.2026

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor n/a
Product bn.js
Versions
  • affected from 0 to 5.2.3 (excl.)

Credits

  • Kr0emer

References

Problem Types

  • Infinite loop