CVE-2026-2739Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-20: 3Technical Details · 2026-02-20: 302-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-2739: The Ghost in the Machine: How an Empty Number Killed the Node.js Event Loop A logic error in the widely used 'bn.js' BigNumber library allows for a Denial of Service via state corruption. By invoking the bitwise masking function with a ... https://cvereports.com/reports/CVE-2026-2739

    Post summary

    The post describes a new denial‑of‑service flaw in the bn.js BigNumber library caused by a logic error, but it provides no evidence of active exploitation, patches, or proof‑of‑concept code.

    0000020
    26 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2739 Denial of Service Vulnerability in bn.js Before 5.2.3 via Maskn Method https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2739

    Post summary

    The entry announces a denial‑of‑service vulnerability in bn.js versions prior to 5.2.3 caused by the Maskn method; no PoC, exploit, or patch details are provided.

    0000040
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2739 This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other method… https://www.cve.org/CVERecord?id=CVE-2026-2739

    Post summary

    CVE-2026-2739 is a vulnerability in bn.js versions before 5.2.3 that corrupts internal state when maskn(0) is called, causing incorrect behavior in functions like toString() and divmod().

    0000061
    56.4K followersView on X

Explore more