CVE-2026-41988
LOWuuid <14.0.0 - Memory Corruption
Title source: llmDescription
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
Scores
CVSS v3
3.2
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
Details
CWE
CWE-670
Status
published
Products (1)
uuidjs/uuid
< 14.0.0
Published
Apr 23, 2026
Tracked Since
Apr 23, 2026