Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 20 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | bn.js: bn.js: Denial of Service via calling maskn(0) | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Indutny
Indutny bn.js |
|
| Vendors & Products |
Indutny
Indutny bn.js |
Fri, 20 Feb 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. | |
| Weaknesses | CWE-835 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-02-20T15:03:53.743Z
Reserved: 2026-02-19T10:59:37.687Z
Link: CVE-2026-2739
No data.
Status : Awaiting Analysis
Published: 2026-02-20T05:17:53.033
Modified: 2026-02-20T13:49:47.623
Link: CVE-2026-2739
OpenCVE Enrichment
Updated: 2026-02-20T09:52:40Z