HIGH7.5
GHSA-6429-3g3w-6mw5
Uncaught Exception in bignum
Details
All versions of the npm package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8. When verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/bignum
Introduced in:
0No fixed version published yet for bignum (npm). Pin to a known-safe version or switch to an alternative.