PatchSiren

uuidjs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Uuidjs CVE published 2026-04-24

CVE-2026-41907

CVE-2026-41907 affects the uuidjs/uuid package used in Node.js. According to the vendor advisory and NVD, versions prior to 14.0.0 do not properly reject out-of-range writes when v3, v5, or v6 are given external output buffers, which can lead to silent partial writes into caller-provided memory. The issue was published on 2026-04-24 and updated on 2026-05-11. The fix is in 14.0.0.

LOW uuidjs CVE published 2026-04-23

CVE-2026-41988

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-23T05:16:05.613Z and has not been modified since then. The vulnerability affects uuidjs uuid versions before 14.0.0, particularly those using UUID versions 3, 5, or 6. The issue can lead to unexpected writes when external output buffers are used.