[Git][security-tracker-team/security-tracker][master] Add CVE-2026-73086/nanoid

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 11 20:58:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
52030876 by Salvatore Bonaccorso at 2026-08-11T21:58:24+02:00
Add CVE-2026-73086/nanoid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -86,7 +86,14 @@ CVE-2026-73088 (Browserslist is a configuration tool for sharing target browsers
 CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5.2 unt ...)
 	TODO: check
 CVE-2026-73086 (nanoid is a secure, URL-friendly, unique string ID generator for JavaS ...)
-	TODO: check
+	- node-postcss 8.5.14+~cs9.3.34-1
+	- node-mocha 9.1.4+ds1+~cs28.2.8-1
+	NOTE: node-postcss bundles nanoid
+	NOTE: node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy
+	NOTE: https://github.com/ai/nanoid/security/advisories/GHSA-xwg4-73v4-xw9w
+	NOTE: Fixed by: https://github.com/ai/nanoid/commit/7087969281cab8ba8ae3babf1894e819068b3bb4 (5.1.11)
+	NOTE: Fixed by: https://github.com/ai/nanoid/commit/821dfed7b5db7f88e92f56c60eef32c8135077c3 (3.3.12)
+	NOTE: Fixed by: https://github.com/ai/nanoid/commit/b0036ed60dc9facd7f1191a50dfb3076500202ac (3.3.12)
 CVE-2026-73085 (Audiobookshelf is a self-hosted audiobook and podcast server. Prior to ...)
 	TODO: check
 CVE-2026-73084 (Activepieces is an open source AI workflow automation platform. Prior  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/52030876bab979a7c885e439e316309fb5c44e83

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/52030876bab979a7c885e439e316309fb5c44e83
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/42fe1cd4/attachment.htm>


More information about the debian-security-tracker-commits mailing list