Skip to content

nanoid@3.3.18 (bundled dependency) is vulnerable to CVE-2026-67214 (no fix on 3.x line) #2131

Description

@chaksaray

Summary

postcss currently depends on nanoid@^3.3.17 (per lib/input.js, lib/map-generator.js) via CommonJS require(). The installed 3.3.18 resolves CVE-2026-67213 (zero-size infinite loop) but remains vulnerable to CVE-2026-67214 (negative-size infinite loop), because the upstream fix (ai/nanoid#601, commit e835c9b) has only been released as nanoid@5.1.16 — no 3.x backport exists upstream.

Why this affects postcss users

postcss cannot currently adopt nanoid@5.x because it's ESM-only, and lib/input.js / lib/map-generator.js load it via require('nanoid/non-secure'), which throws ERR_REQUIRE_ESM. This traps consumers: staying on 3.x carries an unpatched CVE; forcing 5.x breaks the build.

Requested fix (either would resolve this)

  1. Request/track an upstream 3.x backport of the negative-size fix in ai/nanoid (issue: https://github.com/ai/nanoid — the fix is a one-line change, see commit e835c9b71eab832bc6106944bdd26ea96cf2c66d), or
  2. Migrate postcss's internal nanoid usage from require() to a dynamic import() (or lazy-load pattern) so postcss can adopt nanoid@5.x going forward.

Environment

postcss 8.5.26, Node.js (CJS context), nanoid 3.3.18 resolved via yarn resolutions.

Happy to help test a patch if useful.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions