Junglewise Threat Intelligence

CVE-2022-25324: npm bignum uncaught exception in powm

CVE-2022-25324 · Severity: low · CVSS 3.1 · Published 2022-05-07

Vendors: npm.

Executive brief

The npm package bignum is a library for performing arbitrary-precision arithmetic operations on large integers. A vulnerability in the .powm function can crash the Node.js runtime when processing malformed input, causing application availability loss that bypasses normal error-handling mechanisms.

Technical details

The vulnerability is a denial-of-service flaw caused by an uncaught exception in type checking within the V8 JavaScript engine. When the .powm function receives an improperly typed second argument, V8 crashes before Node.js try/catch blocks can intercept the error. The flaw exists in all versions of bignum up to and including 0.13.1. An attacker on a network can send malicious input to trigger the crash, resulting in immediate service termination. No patch is currently available.

Affected products

  • npm bignum all versions up to 0.13.1

Timeline

  • 2022-05-07: disclosed: Advisory published
  • 2022-05-06: other: NVD entry published

References

Related threats