Improper resource allocation In nanoid
Description
nanoid: non-secure generators can loop indefinitely with negative size nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | - | ||
npm | 3.3.16, 5.1.16 | ||
rpm rhel9 | - | - | |
debian 12 | 9.1.4+ds1+~cs28.2.8-1 | ||
debian 13 | 9.1.4+ds1+~cs28.2.8-1 | ||
debian 14 | 9.1.4+ds1+~cs28.2.8-1 | ||
debian 13 | - | ||
debian 14 | 8.5.15+~cs9.3.39-1 |
Aliases
References