Vulnerability Description
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7
- https://github.com/ai/nanoid/releases/tag/5.1.6
- https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-i
FAQ
What is CVE-2026-67213?
CVE-2026-67213 is a vulnerability with a CVSS score of 5.9 (MEDIUM). nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satis...
How severe is CVE-2026-67213?
CVE-2026-67213 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67213?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.