PT-2026-35061 · Pypi · Uuid

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-41907

CVSS v4.0

8.1

High

AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions uuid versions prior to 14.0.0
Description The software used for creating RFC9562 (formerly RFC4122) UUIDs contains an issue where v3, v5, and v6 accept external output buffers but fail to reject out-of-range writes, such as those involving a small buffer or a large offset. This can lead to silent partial writes into buffers provided by the caller.
Recommendations Update to version 14.0.0.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-41907

Affected Products

Uuid