Executive brief
The npm package bignum is a library for performing arbitrary-precision arithmetic operations on large integers. A vulnerability in the .powm function can crash the Node.js runtime when processing malformed input, causing application availability loss that bypasses normal error-handling mechanisms.
Technical details
The vulnerability is a denial-of-service flaw caused by an uncaught exception in type checking within the V8 JavaScript engine. When the .powm function receives an improperly typed second argument, V8 crashes before Node.js try/catch blocks can intercept the error. The flaw exists in all versions of bignum up to and including 0.13.1. An attacker on a network can send malicious input to trigger the crash, resulting in immediate service termination. No patch is currently available.
Affected products
- npm bignum all versions up to 0.13.1
Timeline
- 2022-05-07: disclosed: Advisory published
- 2022-05-06: other: NVD entry published