CVE-2026-41907

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:uuidjs:uuid:*:*:*:*:*:node.js:*:*
cpe:2.3:a:uuidjs:uuid:12.0.0:*:*:*:*:node.js:*:*
cpe:2.3:a:uuidjs:uuid:13.0.0:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-04-24 19:17

Updated : 2026-06-17 10:47


NVD link : CVE-2026-41907

Mitre link : CVE-2026-41907

CVE.ORG link : CVE-2026-41907


JSON object : View

Products Affected

uuidjs

  • uuid
CWE
CWE-787

Out-of-bounds Write

CWE-823

Use of Out-of-range Pointer Offset