uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
Metrics
Affected Vendors & Products
References
History
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Uuidjs
Uuidjs uuid |
|
| Vendors & Products |
Uuidjs
Uuidjs uuid |
Sun, 26 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | uuid: uuid: Unexpected data writes when using external output buffers with specific UUID versions | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 23 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue. | |
| Weaknesses | CWE-670 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-23T04:00:54.960Z
Updated: 2026-04-23T16:22:56.684Z
Reserved: 2026-04-23T04:00:54.532Z
Link: CVE-2026-41988
Updated: 2026-04-23T14:48:58.864Z
Status : Awaiting Analysis
Published: 2026-04-23T05:16:05.613
Modified: 2026-04-24T14:50:56.203
Link: CVE-2026-41988
ReportizFlow