Viz maintains a focused cryptographic library, nano_id, that generates unique identifiers and is embedded across a range of applications and services. The vulnerability signal observed in this vendor centers on insufficient entropy in identifier generation, a structural weakness class that can undermine the uniqueness and unpredictability guarantees the library is designed to provide. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Viz over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36400CRITICAL nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_ | Jun 4, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Viz.
Media articles that mention a CVE ID that affects a product developed by Viz — matched by CVE ID, not by vendor name.