CVE-2026-41988
LOWuuidjs/uuid < 14.0.0 - Unexpected Buffer Writes via UUID v3/5/6 Generation
Title source: llmDescription
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
Scores
CVSS v3
3.2
EPSS
0.0011
EPSS Percentile
1.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-670
Status
published
Products (1)
uuidjs/uuid
< 14.0.0
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026