Vulnerabilities |
2 via 2 paths |
|---|---|
Dependencies |
4 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
high severity
new
- Vulnerable module: nanoid
- Introduced through: nanoid@3.3.17
Detailed paths
-
Introduced through: @authup/vue2@authup/vue2 › nanoid@3.3.17Remediation: Upgrade to nanoid@5.1.16.
Overview
Affected versions of this package are vulnerable to Infinite loop through the customAlphabet and nanoid functions in nanoid/non-secure. An attacker can hang the calling thread by supplying a negative size to either function, causing the loop counter to decrement from a negative value and never reach its termination condition. This affects applications that pass unvalidated attacker-controlled size values into the non-secure ID generator, where a single malicious request can spin the process indefinitely and stop the service from responding.
Notes
- The vulnerable code path is in the
nanoid/non-secureentry point, so bundles or consumers that import the non-secure module directly are the ones exposed; the secure/default package path is a separate export. - The denial-of-service only shows up when callers pass a negative
sizeinto these APIs, which the advisory’s regression tests treat as returning an empty string rather than looping.
Remediation
Upgrade nanoid to version 5.1.16 or higher.
References
high severity
new
- Vulnerable module: nanoid
- Introduced through: nanoid@3.3.17
Detailed paths
-
Introduced through: @authup/vue2@authup/vue2 › nanoid@3.3.17Remediation: Upgrade to nanoid@5.1.16.
Overview
Affected versions of this package are vulnerable to Infinite loop through the customRandom function in the customRandom implementation. An attacker can hang the calling thread by supplying a size of 0 to customRandom, which causes its ID generation loop to never reach a terminating condition. This breaks any application path that accepts an unvalidated, attacker-controlled size and passes it into customRandom, leaving the process stuck while handling the request.
Remediation
Upgrade nanoid to version 5.1.16 or higher.