{"id":"CVE-2026-67213","summary":"nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom","details":"nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.","aliases":["GHSA-2v37-7h3g-55p8"],"modified":"2026-08-12T03:30:13.843617577Z","published":"2026-07-29T13:32:01.534Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67213.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67213.json"},{"type":"ADVISORY","url":"https://github.com/ai/nanoid/releases/tag/5.1.6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67213"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-zero-size-in-customalphabet-and-customrandom"},{"type":"FIX","url":"https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ai/nanoid","events":[{"introduced":"7b45b890ce9cba85c8dc08fdb7ad401b966ed067"},{"fixed":"73d67168136b36fd3b644159b0cff149da4905d9"},{"introduced":"cf151a7476c313ff68c53701c949c287043b9b82"},{"fixed":"c6532dba6f3954b683bd77c71b352c1ee0ed9961"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.3.17"},{"introduced":"5.0.0"},{"fixed":"5.1.6"}]}}],"versions":["3.3.16","3.3.15","3.3.14","3.3.13","3.3.12","5.1.5","3.3.11","3.3.10","5.1.4","3.3.9","5.1.3","3.3.8","5.1.2","5.1.1","5.1.0","5.0.9","3.3.7","5.0.8","5.0.7","5.0.6","5.0.5","5.0.4","5.0.3","3.3.6","5.0.2","5.0.1","5.0.0","3.3.5","3.3.4","3.3.3","3.3.2","3.3.1","3.3.0","3.2.0","3.1.32","3.1.31","3.1.30","3.1.29","3.1.28","3.1.27","3.1.26","3.1.25","3.1.24","3.1.23","3.1.22","3.1.21","3.1.20","3.1.19","3.1.18","3.1.17","3.1.16","3.1.15","3.1.14","3.1.13","3.1.12","3.1.11","3.1.10","3.1.9","3.1.8","3.1.7","3.1.6","3.1.5","3.1.4","3.1.2","3.1.1","3.1.0","3.0.2","3.0.1","3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-67213.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}