Security Advisories์ถœ์ฒ˜: GitHub Security Advisories์กฐํšŒ์ˆ˜ 7

[bn.js] bn.js affected by an infinite loop

By GitHub
2026๋…„ 2์›” 20์ผ
**[bn.js] bn.js affected by an infinite loop**

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely. References https://nvd.nist.gov/vuln/detail/CVE-2026-2739 https://github.com/indutny/bn.js/issues/186 https://github.com/indutny/bn.js/issues/316 https://github.com/indutny/bn.js/pull/317 https://github.com/indutny/bn.js/commit/33df26b5771e824f303a79ec6407409376baa64b https://gist.github.com/Kr0emer/02370d18328c28b5dd7f9ac880d22a91 https://security.snyk.io/vuln/SNYK-JS-BNJS-15274301 https://github.com/indutny/bn.js/releases/tag/v5.2.3 https://github.com/advisories/GHSA-378v-28hj-76wf

---

**[devsupporter ํ•ด์„ค]**

์ด ๊ธฐ์‚ฌ๋Š” GitHub Security Advisories์—์„œ ์ œ๊ณตํ•˜๋Š” ์ตœ์‹  ๊ฐœ๋ฐœ ๋™ํ–ฅ์ž…๋‹ˆ๋‹ค. ๊ด€๋ จ ๋„๊ตฌ๋‚˜ ๊ธฐ์ˆ ์— ๋Œ€ํ•ด ๋” ์•Œ์•„๋ณด์‹œ๋ ค๋ฉด ์›๋ณธ ๋งํฌ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.