Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41988

17
FAUCET Score

CVE-2026-41988 is a vulnerability in uuid versions prior to 14.0.0 that allows unexpected writes to external output buffers when using UUID version 3, 5, or 6. Notably, UUID version 4, the most commonly deployed variant, is not affected by this issue. The vulnerability exists in the uuid library and affects any applications using affected UUID versions with externally-provided output buffers. The vulnerability has a CVSS score of 3.2 (low severity) with a local attack vector requiring high complexity to exploit. The impact is limited to integrity issues with no confidentiality or availability impact. The EPSS score of 0.00012 indicates extremely low exploitation likelihood compared to other CVEs. There is currently no evidence of active exploitation, no public exploit code availability, and the vulnerability has not been added to the Known Exploited Vulnerabilities (KEV) catalog. The issue remains inactive on threat tracking lists, suggesting minimal community attention and real-world exploitation risk at this time. Organizations should still prioritize upgrading to uuid 14.0.0 or later as part of routine patch management, though this does not represent an immediate security threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.1.1CPE matchmatch criteria
cpe:2.3:a:uuidjs:uuid:*:*:*:*:*:node.js:*:*
12.0.0CPE matchmatch criteria
cpe:2.3:a:uuidjs:uuid:12.0.0:*:*:*:*:node.js:*:*
13.0.0CPE matchmatch criteria
cpe:2.3:a:uuidjs:uuid:13.0.0:*:*:*:*:node.js:*:*
>= 0, < 14.0.0CPE match
cpe:2.3:a:uuidjs:uuid:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

3.2LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.4
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
8.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 31st percentile among its peer group of 223 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-41988Low

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID version 4, which is very commonly used, is unaffected by this issue.

Apr 14, 2026

References

github.com / uuidjs/uuid/commit/3d2c5b0342f0fcb52a5ac681c3d47c13e7444b34
Patch
github.com / uuidjs/uuid/security/advisories/GHSA-w5hq-g745-h8pq
ExploitVendor Advisory