THREAT OPS › Threat News › [GHSA] GHSA-xwg4-73v4-xw9w (high) — nanoid: Integer Overflow or Wraparound
[GHSA] GHSA-xwg4-73v4-xw9w (high) — nanoid: Integer Overflow or Wraparound
GHSA-xwg4-73v4-xw9w Severity: high CVE: CVE-2026-73086
nanoid: Integer Overflow or Wraparound
### Summary
An integer overflow in `nanoid(size)` permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string `"uuuuuuuuuuuuuuuuuuuuu"`. Any application that passes user-influenced values to the `size` parameter loses all randomness guarant
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-73086cve
Original source: https://github.com/advisories/GHSA-xwg4-73v4-xw9w