Aller au contenu

Fiche vulnérabilité

CVE-2026-67213 : faille élevée nanoid project nanoid (CVSS 7.5)

Description

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
29 juil. 2026
Dernière mise à jour
18 août 2026

Produits concernés

  • nanoid project nanoid

Références

Rechercher une autre vulnérabilité dans la base CVE