Home

Description

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.

PUBLISHED Reserved 2026-04-23 | Published 2026-04-23 | Updated 2026-04-23 | Assigner mitre




LOW: 3.2CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Problem types

CWE-670 Always-Incorrect Control Flow Implementation

Product status

Default status
unaffected

Any version before 14.0.0
affected

References

github.com/...s/uuid/security/advisories/GHSA-w5hq-g745-h8pq exploit

github.com/...s/uuid/security/advisories/GHSA-w5hq-g745-h8pq

github.com/...ommit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34

cve.org (CVE-2026-41988)

nvd.nist.gov (CVE-2026-41988)

Download JSON