chore(renovate): Security update Update dependency uuid to v14 [SECURITY] - #461
Open
renovate[bot] wants to merge 1 commit into
Open
chore(renovate): Security update Update dependency uuid to v14 [SECURITY]#461renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
requested review from
TilenOman50,
acuderman and
markoftw
as code owners
August 26, 2026 17:40
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 27, 2026 01:43
1a54fa9 to
4077d89
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 2, 2026 20:44
4077d89 to
79b20d2
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 3, 2026 04:07
79b20d2 to
7f86769
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 3, 2026 17:59
7f86769 to
76612f1
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 4, 2026 01:37
76612f1 to
4638c84
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 8, 2026 00:08
4638c84 to
aeb74c4
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 8, 2026 04:52
aeb74c4 to
689ef59
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 9, 2026 23:36
689ef59 to
1e5fdbf
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 10, 2026 04:24
1e5fdbf to
357694b
Compare
…ITY] See associated pull request for more information.
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 10, 2026 15:53
357694b to
f666c38
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^11.0.4→^14.0.2uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41907 / GHSA-w5hq-g745-h8pq
More information
Details
Summary
The
v3(),v5(), andv6()API methods (notuuidrelease versions) accept external output buffers but do not reject out-of-range writes (smallbufor largeoffset).By contrast,
v4(),v1(), andv7()API methods explicitly throwRangeErroron invalid bounds.This inconsistency allows silent partial writes into caller-provided buffers.
Affected code
src/v35.ts(v3()/v5()path) writesbuf[offset + i]without bounds validation.src/v6.tswritesbuf[offset + i]without bounds validation.Reproducible PoC
Observed:
v4() THREW RangeErrorv5() NO_THROWv6() NO_THROWExample partial overwrite evidence captured during audit:
Security impact
Suggested fix
Add the same guard used by
v4()/v1()/v7():Apply to:
src/v35.ts(coversv3()andv5())src/v6.tsSeverity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
uuidjs/uuid (uuid)
v14.0.2Compare Source
Bug Fixes
v14.0.1Compare Source
Bug Fixes
v14.0.0Compare Source
Security
v3(),v5(), andv6()did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalidoffsetwas provided. ARangeErroris now thrown ifoffset < 0oroffset + 16 > buf.length.⚠ BREAKING CHANGES
cryptois now expected to be globally defined (requires node@20+) (#935)v13.0.2Compare Source
Bug Fixes
v13.0.1Compare Source
Bug Fixes
v13.0.0Compare Source
⚠ BREAKING CHANGES
Bug Fixes
v12.0.1Compare Source
Bug Fixes
v12.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
v11.1.1Compare Source
Bug Fixes
v11.1.0Compare Source
Features
Uint8Arraysubtypes forbufferoption (#865) (a5231e7)v11.0.5Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.