CVE-2026-73086

Aliases:RHSA-2026:54412DEBIAN-CVE-2026-73086RHSA-2026:54520GHSA-xwg4-73v4-xw9wCGA-6fjf-ghjq-64c2CGA-766g-46fv-43mvCGA-788m-rwgx-cwmhCGA-7ffr-424v-8j2cCGA-fcvm-pcvf-rhvmCGA-g9ph-4r7w-7phvCGA-29h3-ffp4-474pCGA-2rw4-77m9-xfpwCGA-2vrc-9x7f-3m35CGA-2whp-h6gh-fjv8CGA-36xp-7j3p-fh66CGA-38f5-857x-8f4xCGA-3f7j-g2wq-rmjhCGA-3mm4-p7cm-49grCGA-42x6-mprw-6j39CGA-4cqp-q3jg-6x3fCGA-4cr8-88fg-qx23CGA-4ff9-pqq7-54h8CGA-636p-cq8c-m8q6CGA-66mw-3vx4-g9r6CGA-6c7h-hmwm-gfcmCGA-6hhc-vgmr-pv3gCGA-6j3j-9xf2-rvcjCGA-6phv-43ww-j597CGA-73jc-rhqc-wxg3CGA-73w3-3224-3qmfCGA-75gh-fmhm-vxfpCGA-7crv-6g89-f5x5CGA-7v5w-6x4r-pjq3CGA-82mg-fwjj-cm2fCGA-89jp-cvc7-mcg7CGA-8cjp-qgxh-87r9CGA-8mf9-vm3f-495hCGA-8mjx-jvqj-vh26CGA-8xww-w92j-8whpCGA-9hf2-gm9c-pghmCGA-c8m7-9279-x2wfCGA-f5fq-4997-cm24CGA-g8g6-926g-qccvCGA-gfpw-vhqx-79w2CGA-gx96-fh8q-8fc4CGA-h3q5-g9fp-r485CGA-hfp2-xvr3-g342CGA-hg8c-4fw7-h6h2CGA-jmc5-c577-px78CGA-jqrv-h95r-9xqqCGA-m269-98jc-r2c3CGA-m6pr-5mj3-9w39CGA-mv47-cjfc-mc2vCGA-mvmj-hq7q-g9ggCGA-pmhq-5mj3-xwgfCGA-r3c4-9ghm-fjjwCGA-r927-ccf9-rwxhCGA-rqq2-hwjx-xg69CGA-v29h-8mr4-q8xqCGA-vf96-79rg-9c73CGA-vr3g-f33x-9q55CGA-wqwq-5qv9-pp9xCGA-wr68-cpvm-rff6CGA-x8cp-r6vm-c42wCGA-xfcg-3jgj-p66wCGA-4hr6-vh92-vc4jCGA-4rph-g822-qmp9CGA-6vcr-cm3v-339wCGA-h9wg-ww82-r2ffCGA-7p6q-xcvc-6wv9CGA-jr56-rm7w-6c23CGA-pj8j-3f84-hh98CGA-x3g4-prxw-c2j6CGA-x4cr-hv6q-3rv4
Advisory lineage Upstream: 1 Downstream: 4
Deferred
Published: 11 Aug 2026, 16:46
Last modified:12 Aug 2026, 14:29

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.4 HIGH
v3.1 (cve.org)
EPSS Score
0.3% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Aug 2026, 16:46
Published
Vulnerability first disclosed
12 Aug 2026, 14:29
Last Modified
Vulnerability information updated

Description

nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.30% Percentile: 23%

Techniques & Countermeasures

  • CWE-190Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Affected Systems

  • ainanoid

    < 3.3.12 | ≥ 4.0.0, < 5.1.11

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • chainguardauthentik-fips-2025.12

    all

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardjupyter-base-notebook

    all

  • chainguardtensorflow-gpu-jupyter

    all | < 2.21.0-r9

  • chainguardvitess-22

    all

  • wolfijupyter-base-notebook

    all

  • debiannode-mocha

    all | < 9.1.4+ds1+~cs28.2.8-1 | < 9.1.4+ds1+~cs28.2.8-1 | < 9.1.4+ds1+~cs28.2.8-1

  • debiannode-postcss

    all | all | all | < 8.5.14+~cs9.3.34-1

  • Npmnanoid

    < 3.3.12 | ≥ 4.0.0, < 5.1.11

  • redhatgrafana13.1

    < 0:13.1.3-0.1.hum1

  • redhatprometheus3.5

    < 0:3.5.5-0.8.hum1

References (26)