{"id":"CVE-2026-67213","title":"nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions","summary":"nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins ind…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"nanoid_project","product":"nanoid","affected":["nanoid >= 3.0.0, < 3.3.17","nanoid >= 5.0.0, < 5.1.6"],"patched":["nanoid 5.1.6"],"published":"2026-07-29","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:30.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67213","references":[{"url":"https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ai/nanoid/releases/tag/5.1.6","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-in-customalphabet-and-customrandom","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-29T14:41:51.480372Z"},"epss":0.00587,"epssPercentile":0.46376,"ingestedAt":"2026-10-08T16:52:14.708Z","slug":"CVE-2026-67213","body":"## Overview\n\nnanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.\n\n## Affected\n\n- `nanoid >= 3.0.0, < 3.3.17`\n- `nanoid >= 5.0.0, < 5.1.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nanoid 5.1.6`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}