The Bignum Project maintains a numerical library focused on arbitrary-precision arithmetic operations, with its vulnerability footprint centered on the core bignum product and the application-layer input-handling risks inherent to prototype-based property mutation. The durable signal is rooted in prototype-pollution weakness classes that arise from the handling of object attributes in dynamic language environments. Current vulnerability counts, severity levels, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bignum Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25324HIGH All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, | May 6, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bignum Project.
Media articles that mention a CVE ID that affects a product developed by Bignum Project — matched by CVE ID, not by vendor name.