What is CVE-2026-67214?
CVE-2026-67214 is an infinite loop vulnerability in nanoid (Nano ID) before version 5.1.16, affecting the `customAlphabet` and `nanoid` functions in the non-secure module. Providing a negative size causes the loop to never terminate, potentially leading to a denial of service. Users should upgrade to the latest patched version.
Azərbaycanca: CVE-2026-67214, nanoid (Nano ID) kitabxanasının 5.1.16-dan əvvəlki versiyalarında `customAlphabet` və `nanoid` funksiyalarında sonsuz dövr zəifliyidir. Bu, `nanoid/non-secure` modulunda mənfi ölçü verildikdə baş verir və tətbiqin cavab verməməsinə səbəb ola bilər. Təsirə məruz qalan istifadəçilər kitabxananı ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which nanoid functions are affected by CVE-2026-67214?
This vulnerability affects the `customAlphabet` and `nanoid` functions in the `nanoid/non-secure` module.
What should be done to mitigate CVE-2026-67214?
Affected users should upgrade the nanoid library to version 5.1.16 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.