{"id":"CVE-2026-67214","summary":"nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module","details":"nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.","modified":"2026-07-31T03:49:07.121397322Z","published":"2026-07-29T13:32:02.265Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-835"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67214.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67214.json"},{"type":"ADVISORY","url":"https://github.com/ai/nanoid/releases/tag/5.1.16"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67214"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-module"},{"type":"FIX","url":"https://github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ai/nanoid","events":[{"introduced":"0"},{"fixed":"6ccc67bbaba71d3d77a21d9b636f4171a268ce49"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"5.1.16"}]}}],"versions":["5.1.15","5.1.14","5.1.13","5.1.12","5.1.11","5.1.10","5.1.9","5.1.8","5.1.7","5.1.6","5.1.5","5.1.4","5.1.3","5.1.2","5.1.1","5.1.0","5.0.9","5.0.8","5.0.7","5.0.6","5.0.5","5.0.4","5.0.3","5.0.2","5.0.1","5.0.0","4.0.2","4.0.1","4.0.0","3.3.4","3.3.3","3.3.2","3.3.1","3.3.0","3.2.0","3.1.32","3.1.31","3.1.30","3.1.29","3.1.28","3.1.27","3.1.26","3.1.25","3.1.24","3.1.23","3.1.22","3.1.21","3.1.20","3.1.19","3.1.18","3.1.17","3.1.16","3.1.15","3.1.14","3.1.13","3.1.12","3.1.11","3.1.10","3.1.9","3.1.8","3.1.7","3.1.6","3.1.5","3.1.4","3.1.2","3.1.1","3.1.0","3.0.2","3.0.1","3.0.0","2.1.11","2.1.10","2.1.9","2.1.8","2.1.7","2.1.6","2.1.5","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.3.4","1.3.3","1.3.2","1.3.1","1.3.0","1.2.6","1.2.5","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.1.1","1.1.0","1.0.7","1.0.6","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0","0.2.2","0.2.1","0.2.0","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67214.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}