CVE-2026-67213

Aliases:RHSA-2026:47614UBUNTU-CVE-2026-67213DEBIAN-CVE-2026-67213GHSA-2v37-7h3g-55p8CGA-2h3m-836p-c966CGA-2rg4-xwg7-cwmwCGA-2xhw-pgwm-hc9gCGA-49p9-gxv5-mf8wCGA-626h-8f2q-9cwvCGA-83hc-8mj6-c85jCGA-8f42-grcp-qfmmCGA-9q8v-q8vr-qqr2CGA-c4vf-3gcv-2f62CGA-cgv9-j4v9-984rCGA-cpjh-jfh5-r3w7CGA-fh5f-5fh8-8mhfCGA-fhjh-m6g6-3chwCGA-fpcw-8qp4-4w99CGA-g28v-hmc7-m79hCGA-g8fw-jm33-hgr2CGA-j886-8c9m-ffw9CGA-jp7w-wmhx-ph3jCGA-mx5c-f8f3-8c24CGA-p57f-8cp8-wrm5CGA-ppp3-3569-rwmpCGA-prr5-qwvf-8rc7CGA-px3q-xmvv-3f8xCGA-26xj-m3mr-2hmqCGA-2ff4-w35m-3ghgCGA-32hh-wr5j-m33vCGA-33j8-pr7g-gg5gCGA-375m-9wqw-f4qcCGA-37rg-5xr9-xx86CGA-38pf-jp7q-x6hvCGA-3fqq-gh47-3r9vCGA-3fv6-mr7g-gv9jCGA-3r28-xg8p-5m36CGA-425x-5crh-xxghCGA-4532-pw37-43pgCGA-4fg4-4qv4-8p4gCGA-4g39-755m-82frCGA-4hh9-xrf5-7vvvCGA-4jjc-w934-5cc2CGA-4vcr-hgpf-3qj4CGA-4vwp-69m6-67fvCGA-549w-46jj-49h7CGA-5789-9q6c-9893CGA-5795-vwxj-47xmCGA-57wr-fv96-gp78CGA-5hw7-7pp4-hfpcCGA-5r7c-83q4-5c4cCGA-5rmh-5mg8-wp4wCGA-5rr5-vr7j-c6c4CGA-5whx-g54x-j7cjCGA-626f-g7gw-mgc4CGA-6273-c9f8-wh8wCGA-62c4-223q-38q8CGA-62g6-gq95-96q9CGA-65xh-h5m7-hp52CGA-6699-3p9f-vp5jCGA-6c3m-rm65-3g2xCGA-6jxj-2vj8-p4q8CGA-6qwv-vvp7-mfvfCGA-76fg-2wh9-5m2cCGA-78vm-jmw3-hvqvCGA-79mw-3m3j-m988CGA-7gp4-c7x3-48mjCGA-7jgf-r544-7597CGA-7jj4-r52c-cppjCGA-7mqg-fr64-27fqCGA-7p2x-8xxv-9g4jCGA-7p88-2hh4-hq6mCGA-7x27-jc8m-ggfvCGA-8499-223r-5c3qCGA-885q-925p-vf9fCGA-89v4-hpf4-5c7rCGA-8q9x-p6vh-c33jCGA-8wj8-m28w-4q86CGA-936m-53gw-4qw8CGA-93qj-w6rp-gmvwCGA-96gc-8p64-jvcrCGA-9829-vc8g-9g2rCGA-9898-f359-vg24CGA-9cph-fcm3-695vCGA-9cqw-gc6h-6cgrCGA-9jh9-58c8-v5wjCGA-9mpp-3c4m-4gwgCGA-9wpw-7p5c-vg8mCGA-c6w7-3x9g-rfggCGA-c77p-m2rf-3j79CGA-ccg9-66m2-m7h2CGA-ccx7-f84f-hq3rCGA-cfcp-jcpx-w937CGA-ch86-fcx9-p5q2CGA-chpf-m85q-q844CGA-crgv-x5f7-72hwCGA-cxgg-pf3r-6chxCGA-f4fw-c2qx-h8phCGA-f67r-jx27-v554CGA-fj8c-388p-24f3CGA-fpqc-mw32-f6q5CGA-frhw-572w-7j9vCGA-fv8q-4jwj-qm8pCGA-g35q-fgw2-v6q3CGA-g3v2-vccr-c6wfCGA-g78j-qccf-p5rpCGA-gf4w-mxp5-jx7hCGA-ghv3-vg5h-75rwCGA-gmjr-8x5p-9w77CGA-grm9-j233-925mCGA-gvwr-9gfh-grpvCGA-gwx3-qp9x-42w9CGA-h97j-hf24-pm44CGA-hc3j-7qg3-96wqCGA-hc74-m45v-mr75CGA-hf25-jmqp-8qphCGA-hhxf-qw7j-x3gwCGA-hm3c-cq99-jgmfCGA-hrgv-ff2v-489wCGA-hrqx-gx2p-ccpfCGA-hrx2-3745-v8f8CGA-hvgq-wpfx-rvr5CGA-hx33-x25v-cc65CGA-hxfg-www3-3xhgCGA-j2j9-m86v-xjj7CGA-j83c-wwx2-grq5CGA-jfhg-mpxh-c7r2CGA-jjp4-62m9-m7ffCGA-jmvr-xpc8-39wgCGA-jp6w-mrhf-7mx6CGA-jwwh-6v56-3fgvCGA-m6f3-fj4x-m643CGA-m76c-qhhx-vwmrCGA-mfwp-qgp5-8x2pCGA-mh4w-q33r-5w4pCGA-mj33-xr9p-6x9wCGA-mjh3-4g32-8f82CGA-mr4m-9pff-qgmrCGA-mrh7-9xxp-fmrhCGA-mwf2-xfw8-v839CGA-p56j-ppw2-8jj9CGA-p5mx-j7hr-rv6rCGA-p6j8-hvxg-9r6cCGA-p87x-qjpg-83fgCGA-p8gx-j395-xgjqCGA-q7v7-hp89-hjwwCGA-qg8f-x7g3-5g5qCGA-qhww-8xg2-366gCGA-qj34-94xf-7j74CGA-qmw5-cr6f-gr7hCGA-qvxm-fwr7-gg9cCGA-qwx2-phqr-2gw6CGA-qxjc-397v-56j5CGA-r2vv-qjwf-m76jCGA-r534-qr8g-73q3CGA-r95h-hcr8-v3pqCGA-r9jm-ffcg-6jvvCGA-rgwj-wjrp-4hp9CGA-rjgc-h28f-wfhjCGA-rjw4-7q92-2x92CGA-rmm5-x94r-932xCGA-rwrp-jg5c-pcfjCGA-vgc4-cph3-9fgpCGA-vmrv-48xh-x5mwCGA-w4hq-cjfm-5vhhCGA-w5fh-99hr-h5vjCGA-w6x3-866m-5hx6CGA-w99q-mc6p-w945CGA-wg23-4fp6-24x8CGA-wj28-6m2h-73cwCGA-x5r7-xmhv-vgxmCGA-x83f-x93w-pw32CGA-xh2p-v4fr-5c3xCGA-xjfc-4hx3-pc33CGA-xjmg-2vf2-6qr4CGA-xpm8-q895-v53cCGA-xprh-2gpf-m3jrCGA-xpvr-mrfr-cpg9CGA-xqj2-fhjw-jr76CGA-xrv2-87j3-639wCGA-xrx3-mf57-f83jCGA-278v-pr7x-j7fwCGA-3c96-qv4j-whvpCGA-7cxg-3mpq-4c6qCGA-6vx7-g62c-3cvcCGA-35vg-jcwq-p328CGA-5q99-6fhp-42q9CGA-gq58-4wgc-w6w8CGA-pxwx-qph4-qm85CGA-gwxj-vxp5-hmx8
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 29 Jul 2026, 13:32
Last modified:10 Aug 2026, 15:46

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.2 HIGH
v4.0 (cve.org)
EPSS Score
0.32% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jul 2026, 13:32
Published
Vulnerability first disclosed
10 Aug 2026, 15:46
Last Modified
Vulnerability information updated

Description

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

CVSS Metrics

  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.32% Percentile: 25%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.4-r18

  • chainguardarangodb-3.12

    < 3.12.9.4-r21

  • chainguardauthentik-2025.12

    < 2025.12.6-r7

  • chainguardauthentik-fips-2025.12

    all

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddotstatsuite-supercore

    < 3.1.0_git20260803-r2

  • chainguardgitlab-rails-ce-18.1

    < 18.1.6-r28

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    < 19.0.5-r20

  • chainguardgitlab-rails-ce-19.1

    < 19.1.3-r6

  • chainguardgitlab-rails-ce-19.2

    < 19.2.4-r3

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r1

  • chainguardgitlab-rails-ce-fips-18.1

    < 18.1.6-r90

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.6-r1

  • chainguardgitlab-rails-ce-fips-19.2

    < 19.2.1-r7

  • chainguardhomepage

    < 1.13.2-r11

  • chainguardjitsucom-jitsu-console

    < 2.11.0-r32

  • chainguardjson-server

    < 0.17.4-r11

  • chainguardjupyter-base-notebook

    all

  • chainguardkeep-ui

    < 0.54.2-r4

  • chainguardkeep-ui-fips

    < 0.54.2-r7

  • chainguardkibana-8.17

    all

  • chainguardkibana-8.17-bitnami

    all

  • chainguardkibana-8.17-iamguarded

    all

  • chainguardkibana-9.0

    all

  • chainguardkibana-9.0-bitnami

    all

  • chainguardkibana-9.0-iamguarded

    all

  • chainguardlangfuse-2

    < 2.95.12-r42

  • chainguardlangfuse-2-worker

    < 2.95.12-r42

  • chainguardlangfuse-3

    < 3.225.1-r1

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.225.1-r1

Showing first 50 affected entries in server-rendered view.

References (19)