Skip to content

[GHSA-w5hq-g745-h8pq] uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided#7553

Open
julianladisch wants to merge 1 commit intogithub:julianladisch/advisory-improvement-7553from
julianladisch:julianladisch-GHSA-w5hq-g745-h8pq
Open

[GHSA-w5hq-g745-h8pq] uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided#7553
julianladisch wants to merge 1 commit intogithub:julianladisch/advisory-improvement-7553from
julianladisch:julianladisch-GHSA-w5hq-g745-h8pq

Conversation

@julianladisch
Copy link
Copy Markdown

@julianladisch julianladisch commented Apr 30, 2026

Updates

  • Aliases
  • Affected products
  • References

Comments
This advisory (GHSA-w5hq-g745-h8pq) got CVE-2026-41907, see GHSA-w5hq-g745-h8pq

A duplicate CVE and a duplicate GHSA have been assigned for the identical issue:

This PR adds CVE-2026-41907 and CVE-2026-41988 to Aliases.

This PR adds the duplicate advisories to the references.

The fix has been pack-ported from 14.0.0 to 13.0.1, 12.0.1 and 11.1.1, see GHSA-w5hq-g745-h8pq and https://github.com/uuidjs/uuid/releases

This PR updates the "affected" array with the new ranges and fixes.

@github-actions github-actions Bot changed the base branch from main to julianladisch/advisory-improvement-7553 April 30, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant