CVE-2026-2739
ADVISORY - githubSummary
This affects versions of the package bn.js before 4.12.3 and 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.
EPSS Score: 0.00021 (0.057)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Loop with Unreachable Exit Condition ('Infinite Loop')
ADVISORY - github
Loop with Unreachable Exit Condition ('Infinite Loop')
ADVISORY - redhat
Loop with Unreachable Exit Condition ('Infinite Loop')
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in