Описание
(nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 8.5.15+~cs9.3.39-1build1 |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/resolute | needs-triage | |
| jammy | needs-triage | |
| noble | needs-triage | |
| resolute | needs-triage | |
| upstream | released | 8.5.15+~cs9.3.39-1 |
Показывать по
Ссылки на источники
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.
EPSS
5.9 Medium
CVSS3