uuid
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting uuidpage 1 of 1
- CVE-2026-41907HIGHCVSS 7.5EG 7.5✓ Fixed in 13.0.12026-04-24
uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-p…
- CVE-2026-41988LOWCVSS 2.5EG 2.5✓ Fixed in 11.1.12026-04-23
uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.
Check whether uuid is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for uuid CVEs against the assets you own.
Start Free Scan →