THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xwg4-73v4-xw9w (high) — nanoid: Integer Overflow or Wraparound

[GHSA] GHSA-xwg4-73v4-xw9w (high) — nanoid: Integer Overflow or Wraparound

medgithub_advisoriesPublished 2026-09-01

GHSA-xwg4-73v4-xw9w Severity: high CVE: CVE-2026-73086

nanoid: Integer Overflow or Wraparound

### Summary

An integer overflow in `nanoid(size)` permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string `"uuuuuuuuuuuuuuuuuuuuu"`. Any application that passes user-influenced values to the `size` parameter loses all randomness guarant

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xwg4-73v4-xw9w