Skip to content

chore: bump up nanoid version to v5.1.11 [SECURITY] - #9181

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nanoid-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nanoid-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
nanoid 5.1.5 → 5.1.11 age confidence

nanoid: Integer Overflow or Wraparound

CVE-2026-73086 / GHSA-xwg4-73v4-xw9w

More information

Details

Summary

An integer overflow in nanoid(size) permanently corrupts the process-wide CSPRNG pool, causing all subsequent ID generation to return the deterministic string "uuuuuuuuuuuuuuuuuuuuu". Any application that passes user-influenced values to the size parameter loses all randomness guarantees for session tokens, CSRF tokens, and unique identifiers until process restart.

Details

nanoid() at index.js:101 coerces the size parameter with size |= 0, which converts it to a signed 32-bit integer. When size >= 2^31 (e.g., 2147483648), this wraps to -2147483648.

The negative value is passed to fillPool() (index.js:15):

function fillPool(bytes) {
  if (!pool || pool.length < bytes) {       // false: pool exists, -2B < pool.length
    pool = Buffer.allocUnsafe(bytes * POOL_SIZE_MULTIPLIER)
    crypto.getRandomValues(pool)
    poolOffset = 0
  } else if (poolOffset + bytes > pool.length) {  // false: poolOffset + (-2B) < pool.length
    crypto.getRandomValues(pool)
    poolOffset = 0
  }
  poolOffset += bytes  // poolOffset += -2147483648 → deeply negative
}

Neither branch triggers, so the pool is never refreshed. poolOffset becomes ~-2.1 billion.

Subsequent nanoid() calls execute:

for (let i = poolOffset - size; i < poolOffset; i++) {
  id += scopedUrlAlphabet[pool[i] & 63]
}

pool[negative_index] returns undefined. undefined & 63 evaluates to 0. urlAlphabet[0] is 'u'. Every ID becomes "uuuuuuuuuuuuuuuuuuuuu".

The corruption is persistent — it affects all subsequent calls in the process until ~100 million calls eventually wrap poolOffset back to positive, or the process restarts.

PoC
import { nanoid } from 'nanoid'

// Step 1: Normal operation
console.log(nanoid())  // e.g., "V1StGXR8_Z5jdHi6B-myT"

// Step 2: Trigger overflow (e.g., from an API parameter)
try { nanoid(2147483648) } catch(e) {}

// Step 3: All subsequent IDs are deterministic
console.log(nanoid())  // "uuuuuuuuuuuuuuuuuuuuu"
console.log(nanoid())  // "uuuuuuuuuuuuuuuuuuuuu"
console.log(nanoid())  // "uuuuuuuuuuuuuuuuuuuuu"
// ... forever, process-wide

Run with: node --experimental-vm-modules poc.mjs

Attack scenario: Any API endpoint that accepts a user-controlled length/size parameter (URL shortener slug length, configurable token size, etc.) and passes it to nanoid(userInput).

Impact

Complete loss of ID unpredictability and uniqueness, process-wide, from a single request.

  • All session IDs, CSRF tokens, API keys, and database identifiers generated after the attack are identical and predictable
  • An attacker can predict all tokens issued to other users, enabling session hijacking and authentication bypass
  • The corruption is persistent (survives across requests) and affects all consumers of nanoid in the same process
  • No special privileges or preconditions required — a single unauthenticated request is sufficient
  • Affects any application that passes external input to the size parameter without validation

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

ai/nanoid (nanoid)

v5.1.11

Compare Source

  • Fixed breaking Nano ID by requesting big ID.

v5.1.10

Compare Source

v5.1.9

Compare Source

  • Fixed npm package size regression.

v5.1.8

Compare Source

v5.1.7

Compare Source

v5.1.6

Compare Source

  • Fixed infinite loop on 0 size for customAlphabet.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 2, 2026 03:50
@vercel

vercel Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
blocksuite Ready Ready Preview Oct 5, 2026 3:43pm UTC

This branch was successfully deployed

1 active deployment
Preview — d6ac558b Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

0 participants