PatchOps PatchOps / Incidents / INC-8XVZEFWP

[medium] uuid - uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided #INC-8XVZEFWP

Escalated medium CVE-2026-41907 Repo: izzy-Ti/PatchOps-DevSecOps Opened 1 day ago

Root cause analysis

No root cause recorded.

Security advisory details

### Summary The `v3()`, `v5()`, and `v6()` [API methods](https://github.com/uuidjs/uuid#api-summary) (not `uuid` release versions) accept external output buffers but do not reject out-of-range writes (small `buf` or large `offset`). By contrast, `v4()`, `v1()`, and `v7()` API methods explicitly throw `RangeError` on invalid bounds. This inconsistency allows **silent partial writes** into caller-provided buffers. ### Affected code - `src/v35.ts` (`v3()`/`v5()` path) writes `buf[offset + i]` without bounds validation. - `src/v6.ts` writes `buf[offset + i]` without bounds validation. ### Reproducible PoC ```bash cd /home/StrawHat/uuid npm ci npm run build node --input-type=module -e " import {v4,v5,v6} from './dist-node/index.js'; const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8'; for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)], ]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); } }" ``` Observed: - `v4() THREW RangeError` - `v5() NO_THROW` - `v6() NO_THROW` Example partial overwrite evidence captured during audit: ```text same true buf [ 170, 170, 170, 170, 75, 224, 100, 63 ] v6 [ 187, 187, 187, 187, 31, 19, 185, 64 ] ``` ### Security impact - **Primary**: integrity/robustness issue (silent partial output). - If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error. - In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw. ### Suggested fix Add the same guard used by `v4()`/`v1()`/`v7()`: ```ts if (offset < 0 || offset + 16 > buf.length) { throw new RangeError(`UUID byte range ${offset}:${offset + 15} is out of buffer bounds`); } ``` Apply to: - `src/v35.ts` (covers `v3()` and `v5()`) - `src/v6.ts`

Scanner source GITHUB
Affected version < 11.1.1
Fixed version 11.1.1

Incident metadata

Vulnerability identifier CVE-2026-41907
Correlation ID INC-FCG6EBZ1
Target branch main
Vulnerable commit SHA HEAD~1
Patch iterations 1 of 3

Immutable audit events & agent execution trace

system Vulnerability Ingested
1 day ago
{ "vulnerability_id": 7, "incident_id": 8, "incident_number": "INC-8XVZEFWP", "source": "github", "source_id": "GHSA-w5hq-g745-h8pq", "cve_id": "CVE-2026-41907", "package_name": "uuid", "severity": "medium", "repository": "izzy-Ti/PatchOps-DevSecOps", "is_reopened": false }
system Incident Status_changed
1 day ago
{ "incident_id": 8, "incident_number": "INC-8XVZEFWP", "from_status": "received", "to_status": "triaging", "actor_type": "agent", "actor_id": "triage-agent", "reason": "Automated triage worker initiated" }
system Incident Status_changed
1 day ago
{ "incident_id": 8, "incident_number": "INC-8XVZEFWP", "from_status": "triaging", "to_status": "escalated", "actor_type": "agent", "actor_id": "triage-agent", "reason": "Triage failed [LLM_API_ERROR]: Gemini API error: Gemini API request failed: {\n \"error\": {\n \"code\": 404,\n \"message\": \"models/gemini-1.5-pro-latest is not found for API version v1beta, or is not supported for generateContent. Call ModelService.ListModels to see the list of available models and their supported methods.\",\n \"status\": \"NOT_FOUND\"\n }\n}\n", "error_code": "LLM_API_ERROR", "error_message": "Gemini API error: Gemini API request failed: {\n \"error\": {\n \"code\": 404,\n \"message\": \"models/gemini-1.5-pro-latest is not found for API version v1beta, or is not supported for generateContent. Call ModelService.ListModels to see the list of available models and their supported methods.\",\n \"status\": \"NOT_FOUND\"\n }\n}\n" }
system Workflow Failure_handler_dispatched
1 day ago
{ "incident_id": 8, "incident_number": "INC-8XVZEFWP", "status": "escalated", "job": "App\\Jobs\\HandleIncidentFailureJob" }
system Workflow Failure_handler_dispatched
1 day ago
{ "incident_id": 8, "incident_number": "INC-8XVZEFWP", "status": "escalated", "job": "App\\Jobs\\HandleIncidentFailureJob" }
No patch candidates have been generated yet for this incident.

CI/CD pipeline monitoring & staging verification

Monitors external CI builds, tracks staging deployment, and independently verifies post-deployment environment health.

Remediation run will initialize automatically upon human approval of the candidate patch.