fix(deps): update dependency uuid to v11 [security] - #35
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
May 28, 2026 18:09
889691b to
ceefa4e
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
May 29, 2026 00:05
ceefa4e to
86d202d
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
2 times, most recently
from
June 2, 2026 02:14
61fa2dd to
d23c9ac
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
June 11, 2026 15:54
d23c9ac to
fe8e240
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
June 12, 2026 00:36
fe8e240 to
c7ea03d
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 12, 2026 12:59
c7ea03d to
fa5a9e5
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 12, 2026 19:51
fa5a9e5 to
5fccca8
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 17, 2026 11:35
5fccca8 to
d4e8042
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 17, 2026 12:59
d4e8042 to
8ccf737
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
2 times, most recently
from
July 21, 2026 07:08
75cb523 to
1fa52c1
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 24, 2026 17:31
1fa52c1 to
3daf5ea
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 25, 2026 00:28
3daf5ea to
6d97391
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 30, 2026 17:37
6d97391 to
4e16a0a
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
July 30, 2026 22:02
4e16a0a to
b0e0307
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
2 times, most recently
from
August 12, 2026 04:59
c0cf16b to
e09d014
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 14, 2026 18:28
e09d014 to
09af8ac
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 15, 2026 00:25
09af8ac to
7fb4e0d
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 21, 2026 14:02
7fb4e0d to
2edb916
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 21, 2026 20:38
2edb916 to
3433398
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 26, 2026 17:05
3433398 to
b37c613
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
August 27, 2026 01:01
b37c613 to
e16264a
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 3, 2026 01:07
e16264a to
06731a2
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 3, 2026 05:55
06731a2 to
19161e3
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 3, 2026 20:56
19161e3 to
914a1cb
Compare
renovate
Bot
force-pushed
the
renovate/npm-uuid-vulnerability
branch
from
September 4, 2026 03:36
914a1cb to
a79a3e1
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.3.2→^11.1.1uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41907 / GHSA-w5hq-g745-h8pq
More information
Details
Summary
The
v3(),v5(), andv6()API methods (notuuidrelease versions) accept external output buffers but do not reject out-of-range writes (smallbufor largeoffset).By contrast,
v4(),v1(), andv7()API methods explicitly throwRangeErroron invalid bounds.This inconsistency allows silent partial writes into caller-provided buffers.
Affected code
src/v35.ts(v3()/v5()path) writesbuf[offset + i]without bounds validation.src/v6.tswritesbuf[offset + i]without bounds validation.Reproducible PoC
Observed:
v4() THREW RangeErrorv5() NO_THROWv6() NO_THROWExample partial overwrite evidence captured during audit:
Security impact
Suggested fix
Add the same guard used by
v4()/v1()/v7():Apply to:
src/v35.ts(coversv3()andv5())src/v6.tsSeverity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
uuidjs/uuid (uuid)
v11.1.1Compare Source
Bug Fixes
v11.1.0Compare Source
Features
Uint8Arraysubtypes forbufferoption (#865) (a5231e7)v11.0.5Compare Source
Bug Fixes
v11.0.4Compare Source
Bug Fixes
v1(),v4(), andv7()(#845) (e0ee900)v11.0.3Compare Source
Bug Fixes
v11.0.2Compare Source
Bug Fixes
v11.0.1Compare Source
Bug Fixes
v11.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
v10.0.0Compare Source
⚠ BREAKING CHANGES
Features
Bug Fixes
v9.0.1Compare Source
build
v9.0.0Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.3.2Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.3.1Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.3.0Compare Source
⚠ BREAKING CHANGES
Drop Node.js 10.x support. This library always aims at supporting one EOLed LTS release which by this time now is 12.x which has reached EOL 30 Apr 2022.
Remove the minified UMD build from the package.
Minified code is hard to audit and since this is a widely used library it seems more appropriate nowadays to optimize for auditability than to ship a legacy module format that, at best, serves educational purposes nowadays.
For production browser use cases, users should be using a bundler. For educational purposes, today's online sandboxes like replit.com offer convenient ways to load npm modules, so the use case for UMD through repos like UNPKG or jsDelivr has largely vanished.
Drop IE 11 and Safari 10 support. Drop support for browsers that don't correctly implement const/let and default arguments, and no longer transpile the browser build to ES2015.
This also removes the fallback on msCrypto instead of the crypto API.
Browser tests are run in the first supported version of each supported browser and in the latest (as of this commit) version available on Browserstack.
Features
Bug Fixes
build
drop Node.js 8.x from babel transpile target (#603) (aa11485)
drop support for legacy browsers (IE11, Safari 10) (#604) (0f433e5)
drop node 10.x to upgrade dev dependencies (#653) (28a5712), closes #643
8.3.2 (2020-12-08)
Bug Fixes
8.3.1 (2020-10-04)
Bug Fixes
v8.2.0Compare Source
Features
Bug Fixes
v8.1.0Compare Source
Features
Bug Fixes
v8.0.0Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.3Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.2Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.1Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v7.0.0Compare Source
⚠ BREAKING CHANGES
For native ECMAScript Module (ESM) usage in Node.js only named exports are exposed, there is no more default export.
Deep requiring specific algorithms of this library like
require('uuid/v4'), which has been deprecated inuuid@7, is no longer supported.Instead use the named exports that this module exports.
For ECMAScript Modules (ESM):
For CommonJS:
Features
Bug Fixes
7.0.3 (2020-03-31)
Bug Fixes
7.0.2 (2020-03-04)
Bug Fixes
7.0.1 (2020-02-25)
Bug Fixes
v3.4.0Compare Source
Features
v3.3.3Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.