Bug 2508411 (CVE-2026-67214)

Summary: CVE-2026-67214 nanoid: nanoid: Denial of Service via negative size input in non-secure module functions
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, akhatavk, akostadi, alizardo, amasferr, anjoseph, anpicker, anthomas, anujha, aos-team-art-private, aruklets, aschwart, asdas, asoldano, aszczucz, ataylor, bbaranow, bbrownin, bmaxwell, boliveir, bparees, brasmith, bstansbe, cdrage, cmyers, cochase, dbruscin, dlofthou, dmayorov, dnakabaa, doconnor, dpaolell, dranck, drichtar, dschmidt, dymurray, eborisov, ehelms, ehugonne, ewittman, fmariani, ggainey, gmalinko, gotiwari, gparvin, hasun, ibolton, istudens, ivassile, iweiss, janstey, jchui, jdelft, jfula, jhe, jhorak, jlanda, jlledo, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jupierce, juwatts, jwong, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, lcouzens, lgarciaa, mbiarnes, mcarlett, mdellweg, mhulan, mosmerov, mposolda, msvehla, mvyas, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, osousa, pantinor, pberan, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, ppalepu, ppostler, prdhamdh, prwatson, psrna, ptisnovs, rchan, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, sghai, sidsharm, simaishi, slucidi, smallamp, sseago, ssilvert, stcannon, sthorger, suppawar, syedriko, tcunning, teagle, thjenkin, tmalecek, tsedmik, ttakamiy, vdosoudi, veshanka, vlaad, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size is provided, these functions enter an infinite loop, causing the application to hang indefinitely and disrupting service availability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2523451, 2523452, 2523453, 2523454, 2523456, 2523457, 2523458, 2523459, 2523460, 2523463, 2523464, 2523465, 2523466, 2523467, 2523469, 2523470, 2523473, 2523474, 2523476, 2523477, 2523479, 2523480, 2523481, 2523482, 2523483, 2523484, 2523485, 2523486, 2523487, 2523488, 2523489, 2523449, 2523450, 2523455, 2523461, 2523462, 2523471, 2523472, 2523478    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-29 14:01:51 UTC
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.