CVE-2026-67214
CVE-2026-67214: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-67214] Denial of Service via negative size input in non-secure module functions
CVE-2026-67214Source published Source updated
nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition. A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size…
- Affected products in this advisory
- multicluster engine for Kubernetes 2.17
- multicluster engine for Kubernetes 2.8
- multicluster engine for Kubernetes 2.9
- Red Hat Advanced Cluster Management for Kubernetes 2.11
35 more entries in the full advisory.
- Source-reported affected versions
- < 5.1.16
- Source-reported fixed versions
- 5.1.16
- multicluster-engine/console-mce-rhel9:1786668856
- multicluster-engine/console-mce-rhel9:1787259048
- multicluster-engine/console-mce-rhel9:1787079359
32 more entries in the full advisory.
- Mitigation guidance
- Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.