CVE-2026-41988

LOW

uuid <14.0.0 - Memory Corruption

Title source: llm

Description

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.

Scores

CVSS v3 3.2
EPSS 0.0001
EPSS Percentile 1.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Details

CWE
CWE-670
Status published
Products (1)
uuidjs/uuid < 14.0.0
Published Apr 23, 2026
Tracked Since Apr 23, 2026