CVE-2026-73086
Vulnerability Summary
Timeline
Description
nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.30%• Percentile: 23%
Techniques & Countermeasures
- CWE-190•Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Affected Systems
- ai•nanoid
< 3.3.12 | ≥ 4.0.0, < 5.1.11
- chainguard•airflow-2
all
- chainguard•airflow-core-2
all
- chainguard•authentik-fips-2025.12
all
- chainguard•commercial-gitlab-rails-ee-19.1
all
- chainguard•commercial-gitlab-rails-ee-19.3
all
- chainguard•commercial-gitlab-rails-ee-fips-19.1
all
- chainguard•commercial-gitlab-rails-ee-fips-19.2
all
- chainguard•commercial-gitlab-rails-ee-fips-19.3
all
- chainguard•gitlab-rails-ce-18.10
all
- chainguard•gitlab-rails-ce-18.11
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
all
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-fips-18.10
all
- chainguard•gitlab-rails-ce-fips-18.11
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
all
- chainguard•gitlab-rails-ce-fips-19.0
all
- chainguard•jupyter-base-notebook
all
- chainguard•tensorflow-gpu-jupyter
all | < 2.21.0-r9
- chainguard•vitess-22
all
- wolfi•jupyter-base-notebook
all
- debian•node-mocha
all | < 9.1.4+ds1+~cs28.2.8-1 | < 9.1.4+ds1+~cs28.2.8-1 | < 9.1.4+ds1+~cs28.2.8-1
- debian•node-postcss
all | all | all | < 8.5.14+~cs9.3.34-1
- Npm•nanoid
< 3.3.12 | ≥ 4.0.0, < 5.1.11
- redhat•grafana13.1
< 0:13.1.3-0.1.hum1
- redhat•prometheus3.5
< 0:3.5.5-0.8.hum1
References (26)
- https://github.com/ai/nanoid/security/advisories/GHSA-xwg4-73v4-xw9w
- https://github.com/ai/nanoid/commit/7087969281cab8ba8ae3babf1894e819068b3bb4
- https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3
- https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac
- https://github.com/ai/nanoid/releases/tag/3.3.12
- https://github.com/ai/nanoid/releases/tag/5.1.11
- https://access.redhat.com/errata/RHSA-2026:54412
- https://images.redhat.com/
- https://access.redhat.com/security/cve/CVE-2026-73086
- https://access.redhat.com/security/updates/classification/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54412.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2514175
- https://www.cve.org/CVERecord?id=CVE-2026-73086
- https://nvd.nist.gov/vuln/detail/CVE-2026-73086
- https://security-tracker.debian.org/tracker/CVE-2026-73086
- https://access.redhat.com/errata/RHSA-2026:54520
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54520.json
- https://access.redhat.com/security/cve/CVE-2026-73646
- https://bugzilla.redhat.com/show_bug.cgi?id=2517456
- https://www.cve.org/CVERecord?id=CVE-2026-73646
- https://nvd.nist.gov/vuln/detail/CVE-2026-73646
- https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c
- https://github.com/postcss/postcss/releases/tag/8.5.18
- https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849
- https://github.com/ai/nanoid
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73086.json