Infinite loop in nanoid - CVE-2026-67213
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
Netezza Appliance - Cyclops
How to mitigate CVE-2026-67213
Netezza Appliance - Cyclops - update to 11.3.1.4