CVE-2026-67213
MEDIUM
NVD
CVSS Score
5.9
Severity
MEDIUM
Published
Jul 29, 2026
Vendor
unknown
Description
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.