CVE Vulnerabilities

CVE-2026-67213

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jul 29, 2026 | Modified: Aug 10, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Hardened ImagesRedHatjaeger-main-2.20.0-0.6.hum1*
Red Hat Hardened ImagesRedHatgrafana12-4-main-12.4.6-0.2.hum1*
Red Hat Hardened ImagesRedHatgrafana13-1-main-13.1.1-0.3.hum1*
Node-postcssUbuntuupstream*

References