HIGH
ai
CVE published 2026-08-11
CVE-2026-73086
CVE-2026-73086 nanoid vulnerability debrief. The nanoid library, used for generating secure, URL-friendly unique string IDs in JavaScript, has a high-severity vulnerability prior to versions 3.3.12 and 5.1.11. This issue arises from the handling of the size parameter in the nanoid function, which can be coerced to a signed 32-bit integer, potentially corrupting the process-wide CSPRNG poolOffset. Conseque [truncated]