CVE-2026-41907
EUVD-2026-2560024.04.2026, 19:17
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| uuidjs | uuid | 𝑥 < 11.1.1 |
| uuidjs | uuid | 12.0.0 |
| uuidjs | uuid | 13.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration