Vulnerabilities
Vulnerable Software
Nanoid Project:  >> Nanoid  >> 3.1.1  Security Vulnerabilities
nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-07-29
nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-07-29
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
CVSS Score
4.0
EPSS Score
0.004
Published
2022-01-14


Contact Us

Shodan ® - All rights reserved