CVE-2026-41907

uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset). This allows silent partial writes into caller-provided buffers. This vulnerability is fixed in 14.0.0.

  • Published Apr 24, 2026
  • CVSS 8.1 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available
  • A fix is available

Affected software

In the news

CVE-2026-41907 at the National Vulnerability Database