Medium severity5.9NVD Advisory· Published Jul 29, 2026· Updated Aug 26, 2026
CVE-2026-67214
CVE-2026-67214
Description
nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nanoidnpm | < 3.3.16 | 3.3.16 |
nanoidnpm | >= 4.0.0, < 5.1.16 | 5.1.16 |
Affected products
34- osv-coords32 versionspkg:apk/chainguard/arangodb-3.11pkg:apk/chainguard/arangodb-3.12pkg:apk/chainguard/dotstatsuite-supercorepkg:apk/chainguard/gitlab-rails-ce-18.1pkg:apk/chainguard/gitlab-rails-ce-19.0pkg:apk/chainguard/gitlab-rails-ce-19.1pkg:apk/chainguard/gitlab-rails-ce-19.2pkg:apk/chainguard/gitlab-rails-ce-19.3pkg:apk/chainguard/gitlab-rails-ce-fips-18.1pkg:apk/chainguard/gitlab-rails-ce-fips-19.1pkg:apk/chainguard/gitlab-rails-ce-fips-19.2pkg:apk/chainguard/jitsucom-jitsu-consolepkg:apk/chainguard/langfuse-2pkg:apk/chainguard/langfuse-2-workerpkg:apk/chainguard/langfuse-3pkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-4pkg:apk/chainguard/langfuse-4-workerpkg:apk/chainguard/langfuse-fips-2pkg:apk/chainguard/langfuse-fips-2-workerpkg:apk/chainguard/langfuse-fips-3pkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/langfuse-fips-4pkg:apk/chainguard/langfuse-fips-4-workerpkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/opensearch-dashboards-3-dashboards-mapspkg:apk/chainguard/opensearch-dashboards-3-fips-dashboards-mapspkg:apk/wolfi/jitsucom-jitsu-consolepkg:apk/wolfi/langfuse-3pkg:apk/wolfi/langfuse-3-workerpkg:apk/wolfi/nextcloud-server-33pkg:apk/wolfi/opensearch-dashboards-3-dashboards-maps
< 3.11.14.4-r18+ 31 more
- (no CPE)range: < 3.11.14.4-r18
- (no CPE)range: < 3.12.9.4-r21
- (no CPE)range: < 3.1.0_git20260803-r2
- (no CPE)range: < 18.1.6-r28
- (no CPE)range: < 19.0.5-r20
- (no CPE)range: < 19.1.3-r6
- (no CPE)range: < 19.2.4-r3
- (no CPE)range: < 19.3.1-r1
- (no CPE)range: < 18.1.6-r90
- (no CPE)range: < 19.1.6-r1
- (no CPE)range: < 19.2.1-r7
- (no CPE)range: < 2.11.0-r32
- (no CPE)range: < 2.95.12-r42
- (no CPE)range: < 2.95.12-r42
- (no CPE)range: < 3.225.1-r1
- (no CPE)range: < 3.225.1-r1
- (no CPE)range: < 4.6.0-r0
- (no CPE)range: < 4.6.0-r0
- (no CPE)range: < 2.95.12-r44
- (no CPE)range: < 2.95.12-r44
- (no CPE)range: < 3.224.3-r12
- (no CPE)range: < 3.224.3-r12
- (no CPE)range: < 4.6.0-r2
- (no CPE)range: < 4.6.0-r2
- (no CPE)range: < 33.0.7-r3
- (no CPE)range: < 3.7.0-r16
- (no CPE)range: < 3.7.0-r20
- (no CPE)range: < 2.11.0-r32
- (no CPE)range: < 3.225.1-r1
- (no CPE)range: < 3.225.1-r1
- (no CPE)range: < 33.0.7-r3
- (no CPE)range: < 3.7.0-r16
Patches
Vulnerability mechanics
References
9- github.com/ai/nanoid/commit/6ccc67bbaba71d3d77a21d9b636f4171a268ce49nvdPatchWEB
- www.vulncheck.com/advisories/nanoid-before-infinite-loop-via-negative-size-in-non-secure-modulenvdPatchRelease NotesThird Party AdvisoryWEB
- github.com/advisories/GHSA-28wg-ghj8-5hjvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-67214ghsaADVISORY
- github.com/ai/nanoid/commit/e835c9b71eab832bc6106944bdd26ea96cf2c66dghsaWEB
- github.com/ai/nanoid/pull/600ghsaWEB
- github.com/ai/nanoid/pull/601ghsaWEB
- github.com/ai/nanoid/releases/tag/3.3.16nvdProductRelease Notes
- github.com/ai/nanoid/releases/tag/5.1.16nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.