PatchSiren

Nanoid Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Nanoid Project CVE published 2026-07-29

CVE-2026-67214

CVE-2026-67214 is a denial-of-service vulnerability in the nanoid library, specifically in its non-secure module. The customAlphabet and nanoid functions enter an infinite loop when given a negative size. This issue affects nanoid versions before 3.3.16 and 5.1.16. The vulnerability has a CVSS score of 8.2, indicating high severity. Developers and administrators using nanoid in applications should be awar [truncated]

HIGH nanoid_project CVE published 2026-07-29

CVE-2026-67213

CVE-2026-67213 is a vulnerability in nanoid versions before 5.1.6, where the customAlphabet and customRandom functions enter an infinite loop when configured with a size of 0, potentially leading to a denial-of-service condition. This vulnerability affects applications that pass an unvalidated, attacker-controlled size of 0 to these functions. The CVE record was published on 2026-07-29T14:16:34.890Z and h [truncated]