Infinite loopAffected versions of this package are vulnerable to Infinite loop through the customAlphabet and nanoid functions in nanoid/non-secure. An attacker can hang the calling thread by supplying a negative size to either function, causing the loop counter to decrement from a negative value and never reach its termination condition. This affects applications that pass unvalidated attacker-controlled size values into the non-secure ID generator, where a single malicious request can spin the process indefinitely and stop the service from responding.
Notes
- The vulnerable code path is in the
nanoid/non-secure entry point, so bundles or consumers that import the non-secure module directly are the ones exposed; the secure/default package path is a separate export.
- The denial-of-service only shows up when callers pass a negative
size into these APIs, which the advisory’s regression tests treat as returning an empty string rather than looping.
How to fix Infinite loop? Upgrade org.webjars.npm:nanoid to version 3.3.16, 5.1.16 or higher.
| |
Infinite loopAffected versions of this package are vulnerable to Infinite loop through the customRandom function in the customRandom implementation. An attacker can hang the calling thread by supplying a size of 0 to customRandom, which causes its ID generation loop to never reach a terminating condition. This breaks any application path that accepts an unvalidated, attacker-controlled size and passes it into customRandom, leaving the process stuck while handling the request.
How to fix Infinite loop? Upgrade org.webjars.npm:nanoid to version 5.1.6 or higher.
| |