CVE-2026-67214

Aliases:UBUNTU-CVE-2026-67214DEBIAN-CVE-2026-67214GHSA-28wg-ghj8-5hjvRHSA-2026:48320RHSA-2026:59030CGA-2327-mx34-26j4CGA-45cf-cm7j-rmjcCGA-4pgx-vj5q-cjhwCGA-5f26-7qwq-rqgpCGA-5v7q-8c6p-f26rCGA-6v6x-pmfx-g284CGA-893x-74f4-2mwfCGA-9594-4r3p-q2m4CGA-c54w-gpvf-vhrgCGA-cmm6-ph5q-pv4gCGA-f2rh-3fvr-vgvhCGA-gh3w-w457-2h38CGA-mjw5-rgq9-cwc2CGA-pvh9-mf8r-r65pCGA-2448-qxvc-m6ffCGA-25q8-3jjm-8whqCGA-26ch-cv7m-hcx5CGA-277r-r6f4-r8wjCGA-278j-g77w-8xr5CGA-2fhw-mw3g-47cvCGA-2g5c-jvm4-m5jwCGA-2jf3-wrff-6qrhCGA-2x24-88wx-qr4pCGA-352j-h9qp-5287CGA-35ww-wrgv-276wCGA-396h-999v-f489CGA-3c5f-hrfx-c666CGA-3cfm-25wr-r3jhCGA-3f9r-j5pq-wmg2CGA-3g9q-pvv3-j657CGA-3hq5-8j96-rcpwCGA-3qrf-qpj9-q98pCGA-3rh8-636h-3wq4CGA-454m-pvcw-2h9vCGA-484r-m9x5-w6gpCGA-4hpp-vxph-7xwqCGA-4w5w-5wrc-58ppCGA-4wj6-cf97-fm39CGA-4xr3-gw97-mqj5CGA-5248-x9c5-hm96CGA-57f9-22mw-44qvCGA-585q-mcmf-2rp5CGA-58pp-j94g-v4gqCGA-5gr9-jm2j-jpq4CGA-5h7j-96hh-qr4gCGA-5qp5-qrrp-49xvCGA-5qwc-r2v8-77hqCGA-5rvv-63jv-h4m6CGA-5vm6-xjwg-h852CGA-5vrv-mwxx-f5wrCGA-6j24-h99c-3mg5CGA-6jxh-f7xj-gpj7CGA-6vgg-m8mh-vpxhCGA-6xww-qcg3-cx8hCGA-72rq-g79q-vvw4CGA-75v3-3vj3-xh4cCGA-7737-6v8v-q229CGA-77cm-jh6f-f5mxCGA-7862-m3gj-gxrfCGA-7899-vgcq-6hrqCGA-7w67-34gv-pmwwCGA-82jw-r77h-9w33CGA-874x-8q95-j7c5CGA-8jjm-j35m-p76hCGA-8rpq-56v4-w897CGA-95qj-qf7x-85h5CGA-9658-9v5m-9fh4CGA-9hfh-p42c-r9x9CGA-9mx7-m6vh-23g2CGA-9prf-x3gg-4hpxCGA-9rj4-x4q5-c5gmCGA-9wf5-652r-gg5fCGA-9wp2-m5g3-3w76CGA-9xf5-7962-wxc8CGA-c343-3x65-q8mrCGA-c8h7-wfv4-87m5CGA-c8r3-2ccf-94h8CGA-crpx-9mq3-vr6wCGA-cw9q-3pmp-5p69CGA-f587-9vc2-fpq2CGA-f733-7659-pf76CGA-f86q-hj6p-3chgCGA-fcxv-v76g-6cjfCGA-fmhc-wgfv-gq9rCGA-fq3c-wmqc-j5x4CGA-g269-rx5f-chjpCGA-g9h2-jqc8-cr3xCGA-gf67-x5w5-pxr9CGA-ggmc-vq2w-q59hCGA-gh2f-8q43-6h4fCGA-gjwf-295r-4mf8CGA-gmgv-rhcc-v7ppCGA-h33v-jcm8-v944CGA-h8vv-mxjq-vmfqCGA-hc4c-2gr6-r98jCGA-hj88-78p2-8mwmCGA-hjc2-hqfx-m6q4CGA-hjp8-w4jx-4v2pCGA-hmqf-qhpq-wmq2CGA-hx8h-8mv7-6vcqCGA-hxf7-xhq4-5xccCGA-j2q5-8frp-7m26CGA-j3jj-c45h-9rmrCGA-j6f8-4hm4-j2ccCGA-j8vf-fm27-jq4hCGA-m5j3-w259-82c8CGA-m95x-p96f-vwwfCGA-mc6h-9r53-8jx2CGA-mf5j-9j24-v6rvCGA-mfwg-f548-wrw8CGA-mghm-77r9-84jxCGA-p5pv-pqjc-fx9fCGA-q5hr-5mfc-5m5wCGA-q9f6-fr54-7pp2CGA-qfqg-w872-x47mCGA-qhjm-phfw-cgm7CGA-qmcp-6j7g-xxg3CGA-qqhc-r589-r5gjCGA-qrpj-2h6q-qcw4CGA-qwc9-5ggr-6xvrCGA-r2f4-45g5-pqm2CGA-r55f-x3m5-wgwjCGA-r736-2g5x-8cf2CGA-r77w-pxph-6xmmCGA-r8r2-5pjq-m9mrCGA-rh92-x2qc-9f6jCGA-rmw2-f6v5-f2x3CGA-rp36-p2jg-7pf5CGA-rv89-6x6h-cwjqCGA-rxj5-582c-2qcxCGA-v379-77jw-v46wCGA-v3wj-m8gm-383gCGA-vcmm-49px-m86cCGA-vqc8-rxr4-xcm9CGA-vrf2-9c3m-3vcwCGA-vwpj-23fx-975mCGA-w63m-hm66-469qCGA-w8j9-crx3-6mwmCGA-wc3j-87m6-6rfrCGA-wc85-p838-r83rCGA-wh2c-4ppr-qjm4CGA-wrgh-r467-8w7rCGA-wwv5-v55v-ph53CGA-x3xj-ggpc-25w9CGA-x8cx-f9jc-3893CGA-xf3h-7vgv-wj3rCGA-xf58-g2gx-c98xCGA-xp2p-mqw7-pvm4CGA-3cjv-29hf-rv94CGA-8p54-q5fr-98xwCGA-jj8j-hv8c-54c9CGA-2fvg-9g88-5vv3CGA-qwfq-xch3-22qxCGA-34cq-64ph-c859CGA-69p9-jv44-mgpvCGA-p3qv-2544-2778CGA-rh3v-g7h9-69cfCGA-3p98-j95g-f38j
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Analyzed
Published: 29 Jul 2026, 13:32
Last modified:19 Aug 2026, 20:26

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.2 HIGH
v4.0 (cve.org)
EPSS Score
0.33% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jul 2026, 13:32
Published
Vulnerability first disclosed
19 Aug 2026, 20:26
Last Modified
Vulnerability information updated

Description

nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.

CVSS Metrics

  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.33% Percentile: 26%

Techniques & Countermeasures

  • CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')

    The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardarangodb-3.11

    < 3.11.14.4-r18

  • chainguardarangodb-3.12

    < 3.12.9.4-r21

  • chainguardauthentik-fips-2025.12

    all

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguarddotstatsuite-supercore

    < 3.1.0_git20260803-r2

  • chainguardgitlab-rails-ce-18.1

    < 18.1.6-r28

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    < 19.0.5-r20

  • chainguardgitlab-rails-ce-19.1

    < 19.1.3-r6

  • chainguardgitlab-rails-ce-19.2

    < 19.2.4-r3

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r1

  • chainguardgitlab-rails-ce-fips-18.1

    < 18.1.6-r90

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    < 19.1.6-r1

  • chainguardgitlab-rails-ce-fips-19.2

    < 19.2.1-r7

  • chainguardjitsucom-jitsu-console

    < 2.11.0-r32

  • chainguardjupyter-base-notebook

    all

  • chainguardkibana-9.0

    all

  • chainguardkibana-9.0-bitnami

    all

  • chainguardkibana-9.0-iamguarded

    all

  • chainguardlangfuse-2

    < 2.95.12-r42

  • chainguardlangfuse-2-worker

    < 2.95.12-r42

  • chainguardlangfuse-3

    < 3.225.1-r1

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.225.1-r1

  • chainguardlangfuse-4

    < 4.6.0-r0

  • chainguardlangfuse-4-worker

    < 4.6.0-r0

  • chainguardlangfuse-fips-2

    < 2.95.12-r44

  • chainguardlangfuse-fips-2-worker

    < 2.95.12-r44

  • chainguardlangfuse-fips-3

    < 3.224.3-r12

  • chainguardlangfuse-fips-3-worker

    < 3.224.3-r12

  • chainguardlangfuse-fips-4

    < 4.6.0-r2

Showing first 50 affected entries in server-rendered view.

References (28)