CVE-2025-3194Patch

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attackers can exploit this to crash the application.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-09: 1Patch / Workaround · 2026-03-09: 103-09
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • heathen@heathenft
    Patch

    If you're still on [at]solana/web3.js v1 and npm audit is flagging bigint-buffer (CVE-2025-3194), here's a pure JS drop-in replacement. Zero dependencies, works in browsers, and no more "Failed to load bindings" warnings. npm overrides swap in your package.json, and you're done.

    Post summary

    Suggests using a pure JavaScript drop‑in replacement and npm overrides to mitigate CVE‑2025‑3194, effectively acting as a patch.

    260228705
    3.8K followersView on X

Explore more