Nanoid Nanoidproject Nanoid

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Nanoidproject Nanoid.

By the Year

In 2026 there have been 2 vulnerabilities in Nanoidproject Nanoid with an average score of 5.9 out of ten. Nanoid did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 2 5.90
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 1 4.00

It may take a day or so for new Nanoid vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Nanoidproject Nanoid Security Vulnerabilities

DoS via Infinite Loop in nanoid <=5.1.6 CustomAlphabet
CVE-2026-67213 5.9 - Medium - July 29, 2026

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

Infinite Loop

nanoid (Non-secure) before 5.1.16 DOS via Infinite Loop on Negative Size
CVE-2026-67214 5.9 - Medium - July 29, 2026

nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.

Infinite Loop

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which
CVE-2021-23566 4 - Medium - January 14, 2022

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Nanoidproject Nanoid or by Nanoidproject? Click the Watch button to subscribe.

subscribe