Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-67213

Опубликовано: 29 июл. 2026
Источник: debian

Описание

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-postcssfixed8.5.8+~cs9.3.30-1package
node-mochafixed9.1.4+ds1+~cs28.2.8-1package
node-mochapostponedbullseyepackage

Примечания

  • node-postcss bundles nanoid

  • node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy

  • Fixed by: https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7 (5.1.6)

Связанные уязвимости

CVSS3: 5.9
ubuntu
5 дней назад

(nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)

CVSS3: 5.9
nvd
5 дней назад

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

CVSS3: 5.9
github
5 дней назад

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.