Skip to content

[GHSA-w5hq-g745-h8pq] uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided#7553

Merged
advisory-database[bot] merged 1 commit intogithub:julianladisch/advisory-improvement-7553from
julianladisch:julianladisch-GHSA-w5hq-g745-h8pq
May 5, 2026
Merged

[GHSA-w5hq-g745-h8pq] uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided#7553
advisory-database[bot] merged 1 commit intogithub:julianladisch/advisory-improvement-7553from
julianladisch:julianladisch-GHSA-w5hq-g745-h8pq

Conversation

@julianladisch
Copy link
Copy Markdown

@julianladisch julianladisch commented Apr 30, 2026

Updates

  • Aliases
  • Affected products
  • References

Comments
This advisory (GHSA-w5hq-g745-h8pq) got CVE-2026-41907, see GHSA-w5hq-g745-h8pq

A duplicate CVE and a duplicate GHSA have been assigned for the identical issue:

This PR adds CVE-2026-41907 and CVE-2026-41988 to Aliases.

This PR adds the duplicate advisories to the references.

The fix has been pack-ported from 14.0.0 to 13.0.1, 12.0.1 and 11.1.1, see GHSA-w5hq-g745-h8pq and https://github.com/uuidjs/uuid/releases

This PR updates the "affected" array with the new ranges and fixes.

@github-actions github-actions Bot changed the base branch from main to julianladisch/advisory-improvement-7553 April 30, 2026 10:46
@julianladisch julianladisch force-pushed the julianladisch-GHSA-w5hq-g745-h8pq branch from a3f7680 to 09369d6 Compare April 30, 2026 11:10
@advisory-database advisory-database Bot merged commit 8a38fef into github:julianladisch/advisory-improvement-7553 May 5, 2026
1 check passed
@advisory-database
Copy link
Copy Markdown
Contributor

Hi @julianladisch! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@taladrane
Copy link
Copy Markdown
Collaborator

GHSA-w5hq-g745-h8pq has been updated to include CVE-2026-41907 and GHSA-qmq6-f8pr-cx5x was withdrawn as a duplicate of that 🎉

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants