CVE-2026-41988 is a vulnerability in uuid versions prior to 14.0.0 that allows unexpected writes to external output buffers when using UUID version 3, 5, or 6. Notably, UUID version 4, the most commonly deployed variant, is not affected by this issue. The vulnerability exists in the uuid library and affects any applications using affected UUID versions with externally-provided output buffers. The vulnerability has a CVSS score of 3.2 (low severity) with a local attack vector requiring high complexity to exploit. The impact is limited to integrity issues with no confidentiality or availability impact. The EPSS score of 0.00012 indicates extremely low exploitation likelihood compared to other CVEs. There is currently no evidence of active exploitation, no public exploit code availability, and the vulnerability has not been added to the Known Exploited Vulnerabilities (KEV) catalog. The issue remains inactive on threat tracking lists, suggesting minimal community attention and real-world exploitation risk at this time. Organizations should still prioritize upgrading to uuid 14.0.0 or later as part of routine patch management, though this does not represent an immediate security threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.1.1CPE matchmatch criteria | cpe:2.3:a:uuidjs:uuid:*:*:*:*:*:node.js:*:* | ||
12.0.0CPE matchmatch criteria | cpe:2.3:a:uuidjs:uuid:12.0.0:*:*:*:*:node.js:*:* | ||
13.0.0CPE matchmatch criteria | cpe:2.3:a:uuidjs:uuid:13.0.0:*:*:*:*:node.js:*:* | ||
>= 0, < 14.0.0CPE match | cpe:2.3:a:uuidjs:uuid:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.