What is CVE-2026-67213?
CVE-2026-67213 is an infinite loop vulnerability in the nanoid library before version 5.1.6, affecting the `customAlphabet` and `customRandom` functions. When a size of 0 is configured, the internal generation loop fails to exit, causing the calling thread to hang and resulting in a Denial of Service condition. Upgrading nanoid to version 5.1.6 or later is required to fix this issue.
Azərbaycanca: CVE-2026-67213 nanoid kitabxanasının 5.1.6 versiyasından əvvəlki versiyalarında `customAlphabet` və `customRandom` funksiyalarında sonsuz dövr (infinite loop) zəifliyidir. Ölçü (size) 0 olaraq təyin edildikdə, bu funksiyalar dayanmır və cavabdeh olan thread-i asaraq xidmət əngəlinə (Denial of Service) səbəb olur. Bu problemdən qorunmaq üçün nanoid kitabxanasını ən azı 5.1.6 versiyasına yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of the nanoid library are affected by CVE-2026-67213?
All versions of the nanoid library before version 5.1.6 are affected by this vulnerability.
What action is required to mitigate CVE-2026-67213?
Upgrading the nanoid library to version 5.1.6 or later is required to fix this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.