{"id":"CVE-2026-67214","title":"nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure)","summary":"nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented …","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"nanoid_project","product":"nanoid","affected":["nanoid < 3.3.16","nanoid >= 4.0.0, < 5.1.16"],"patched":["nanoid 5.1.16"],"published":"2026-07-29","updated":"2026-09-30","sourceUpdated":"2026-09-30T16:54:12.183","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67214","references":[{"url":"https://github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ai/nanoid/releases/tag/3.3.16","label":"disclosure@vulncheck.com"},{"url":"https://github.com/ai/nanoid/releases/tag/5.1.16","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.0033,"epssPercentile":0.23675,"ingestedAt":"2026-09-30T17:13:20.782Z","slug":"CVE-2026-67214","body":"## Overview\n\nnanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.\n\n## Affected\n\n- `nanoid < 3.3.16`\n- `nanoid >= 4.0.0, < 5.1.16`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nanoid 5.1.16`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}