Executive brief
Nano ID is a popular JavaScript library for generating secure, unique identifiers. When the customAlphabet or customRandom functions are called with a size parameter of zero, the library enters an infinite loop that hangs the application thread, causing a denial-of-service. An attacker who can control the size parameter passed to these functions can crash applications using vulnerable versions.
Technical details
This vulnerability (CWE-835: Infinite Loop) exists in the customAlphabet and customRandom functions of the Nano ID library. The generation loop in these functions fails to handle a zero or negative size parameter, resulting in an exit condition that can never be satisfied. When an application passes an attacker-controlled size value of 0 to these functions without prior validation, the thread executing the function will hang indefinitely, consuming CPU resources and rendering the application unresponsive. The vulnerability affects all versions before 3.3.18 (for the 0.x–3.x branch) and before 5.1.6 (for the 4.x–5.x branch). Patches have been released that add explicit validation to reject zero and negative size parameters, either by throwing an error or returning an empty string depending on the code path.
Affected products
- ai nanoid before 3.3.18 and 4.0.0 before 5.1.6
Timeline
- 2026-07-29: disclosed: Vulnerability published to advisories
- 2026-08-03: patched: Fixes released in versions 3.3.18 and 5.1.6
References
- https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7
- https://github.com/ai/nanoid/commit/e10f8d40ce9d1ab47f66d65a16b48086432730d0
- https://github.com/ai/nanoid/commit/f9d13f150847d117877adee3460a46eceb0cf49b
- https://github.com/ai/nanoid
- https://github.com/ai/nanoid/releases/tag/3.3.17
- https://github.com/ai/nanoid/releases/tag/3.3.18