Bug 2508411 (CVE-2026-67214)
| Summary: | CVE-2026-67214 nanoid: nanoid: Denial of Service via negative size input in non-secure module functions | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | abarbaro, akhatavk, akostadi, alizardo, amasferr, anjoseph, anpicker, anthomas, anujha, aos-team-art-private, aruklets, aschwart, asdas, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, boliveir, bparees, brasmith, bstansbe, cdrage, cmyers, cochase, dbruscin, dlofthou, dmayorov, dnakabaa, doconnor, dpaolell, dranck, drichtar, dschmidt, dymurray, eborisov, ehelms, ehugonne, ewittman, fmariani, ggainey, gmalinko, gotiwari, gparvin, hasun, ibolton, istudens, ivassile, iweiss, janstey, jchui, jdelft, jfula, jhe, jhorak, jlanda, jlledo, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jupierce, juwatts, jwong, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, lcouzens, lgarciaa, mbiarnes, mcarlett, mdellweg, mhulan, mosmerov, mposolda, msvehla, mvyas, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, osousa, pantinor, pberan, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, ppalepu, ppostler, prdhamdh, prwatson, psrna, ptisnovs, rchan, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, sseago, ssilvert, stcannon, sthorger, suppawar, syedriko, tcunning, teagle, thjenkin, tmalecek, tsedmik, ttakamiy, vdosoudi, veshanka, vlaad, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2523451, 2523452, 2523453, 2523454, 2523456, 2523457, 2523458, 2523459, 2523460, 2523463, 2523464, 2523465, 2523466, 2523467, 2523469, 2523470, 2523473, 2523474, 2523476, 2523477, 2523479, 2523480, 2523481, 2523482, 2523483, 2523484, 2523485, 2523486, 2523487, 2523488, 2523489, 2523449, 2523450, 2523455, 2523461, 2523462, 2523471, 2523472, 2523478 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-07-29 14:01:51 UTC
|