CVE-2024-55565

Aliases:GHSA-mwcw-c2x4-8c55DEBIAN-CVE-2024-55565CGA-4gj9-cj62-6f43CGA-5252-3r4m-9x5hCGA-5qqr-qv85-w995CGA-5r52-jjm7-c992CGA-8v8p-p856-9fgcCGA-9347-2mx9-g7fqCGA-f83v-xhf8-fx77CGA-gcfc-m97p-fghgCGA-gm69-8xj5-jv25CGA-gr2f-7wh4-gq7fCGA-hcrr-9w3g-v2gjCGA-hm2w-p7ph-867qCGA-hrw2-qg33-3gf2CGA-p6cr-3mjm-j4j5CGA-pg2w-mp4v-9g7mCGA-3mcw-8gp2-32vrCGA-4fcc-cr2c-mfj6CGA-6hj8-mchp-r2wvCGA-jq2v-r2r8-hrhvCGA-qpg6-jhj7-25x3CGA-rw99-qvm5-c5gmCGA-v6f8-26gf-vhrvCGA-wf37-p5hq-fc23CGA-x3j4-pcpv-7945CGA-xj8j-vxp3-v8fxCGA-5737-fp97-xm78CGA-9c8j-gwrf-xjg6
Advisory lineage Upstream: 0 Downstream: 7
Deferred
Published: 09 Dec 2024, 00:00
Last modified:03 Nov 2025, 22:32

Vulnerability Summary

Overall Risk (default)
low
17/100
CVSS Score
4.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.66% LOW
1% probability +0.55%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Dec 2024, 00:00
Published
Vulnerability first disclosed
03 Nov 2025, 22:32
Last Modified
Vulnerability information updated

Description

nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.

CVSS Metrics

  • v3.1MEDIUMScore: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.66% Percentile: 50%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Systems

  • chainguardarangodb-3.11

    < 3.11.14.4-r18

  • chainguardarangodb-3.12

    < 3.12.9.4-r21

  • chainguardjitsucom-jitsu

    < 2.8.5-r0

  • chainguardjitsucom-jitsu-console

    < 2.8.5-r0

  • chainguardjitsucom-jitsu-rotor

    < 2.8.5-r0

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfijitsucom-jitsu

    < 2.8.5-r0

  • wolfijitsucom-jitsu-console

    < 2.8.5-r0

  • wolfijitsucom-jitsu-rotor

    < 2.8.5-r0

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • debiannode-mocha

    < 8.2.1+ds1+~cs29.4.27-3+deb11u1 | < 9.1.4+ds1+~cs28.2.8-1 | < 9.1.4+ds1+~cs28.2.8-1 | < 9.1.4+ds1+~cs28.2.8-1

  • debiannode-postcss

    < 8.2.1+~cs5.3.23-8+deb11u1 | < 8.4.20+~cs8.0.23-1+deb12u1 | < 8.4.49+~cs9.2.32-1 | < 8.4.49+~cs9.2.32-1

  • Npmnanoid

    ≥ 4.0.0, < 5.0.9 | < 3.3.8

References (9)