Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-67214

CVE-2026-67214: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-67214] Denial of Service via negative size input in non-secure module functions

    CVE-2026-67214Source published Source updated

    nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition. A flaw was found in nanoid (Nano ID), a JavaScript library used for generating unique identifiers. This vulnerability allows an attacker to cause a Denial of Service (DoS) by providing a negative size input to the customAlphabet or nanoid functions within the library's non-secure module. When a negative size…

    Affected products in this advisory
    • multicluster engine for Kubernetes 2.17
    • multicluster engine for Kubernetes 2.8
    • multicluster engine for Kubernetes 2.9
    • Red Hat Advanced Cluster Management for Kubernetes 2.11

    35 more entries in the full advisory.

    Source-reported affected versions
    • < 5.1.16
    Source-reported fixed versions
    • 5.1.16
    • multicluster-engine/console-mce-rhel9:1786668856
    • multicluster-engine/console-mce-rhel9:1787259048
    • multicluster-engine/console-mce-rhel9:1787079359

    32 more entries in the full advisory.

    Mitigation guidance
    • Sanitize all user-supplied integer inputs before passing them to `nanoid` or `customAlphabet` functions in the `nanoid/non-secure` module, ensuring the size parameter is strictly a non-negative integer.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery