PatchSiren

nanoid_project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH nanoid_project CVE published 2026-07-29

CVE-2026-67213

CVE-2026-67213 is a vulnerability in nanoid versions before 5.1.6, where the customAlphabet and customRandom functions enter an infinite loop when configured with a size of 0, potentially leading to a denial-of-service condition. This vulnerability affects applications that pass an unvalidated, attacker-controlled size of 0 to these functions. The CVE record was published on 2026-07-29T14:16:34.890Z and h [truncated]