Skip to content

fix(deps): update dependency uuid to v14 [security]#4298

Open
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/npm-uuid-vulnerability
Open

fix(deps): update dependency uuid to v14 [security]#4298
renovate-bot wants to merge 1 commit intoGoogleCloudPlatform:mainfrom
renovate-bot:renovate/npm-uuid-vulnerability

Conversation

@renovate-bot
Copy link
Copy Markdown
Contributor

@renovate-bot renovate-bot commented Apr 23, 2026

This PR contains the following updates:

Package Change Age Confidence
uuid ^10.0.0^14.0.0 age confidence
uuid ^8.0.0^14.0.0 age confidence
uuid ^11.0.5^14.0.0 age confidence
uuid ^11.1.0^14.0.0 age confidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

GHSA-w5hq-g745-h8pq

More information

Details

Summary

v3, v5, and v6 accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4, v1, and v7 explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3/v5 path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build

node --input-type=module -e "
import {v4,v5,v6} from './dist-node/index.js';
const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';
for (const [name,fn] of [
  ['v4',()=>v4({},new Uint8Array(8),4)],
  ['v5',()=>v5('x',ns,new Uint8Array(8),4)],
  ['v6',()=>v6({},new Uint8Array(8),4)],
]) {
  try { fn(); console.log(name,'NO_THROW'); }
  catch(e){ console.log(name,'THREW',e.name); }
}"

Observed:

  • v4 THREW RangeError
  • v5 NO_THROW
  • v6 NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
  170, 170, 170, 170,
   75, 224, 100,  63
]
v6 [
  187, 187, 187, 187,
   31,  19, 185,  64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4/v1/v7:

if (offset < 0 || offset + 16 > buf.length) {
  throw new RangeError(`UUID byte range ${offset}:${offset + 15} is out of buffer bounds`);
}

Apply to:

  • src/v35.ts (covers v3 and v5)
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v14.0.0

Compare Source

Security
  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.
⚠ BREAKING CHANGES
  • crypto is now expected to be globally defined (requires node@​20+) (#​935)
  • drop node@​18 support (#​934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

v13.0.0

Compare Source

⚠ BREAKING CHANGES
  • make browser exports the default (#​901)
Bug Fixes

v12.0.0

Compare Source

⚠ BREAKING CHANGES
  • update to typescript@​5.2 (#​887)
  • remove CommonJS support (#​886)
  • drop node@​16 support (#​883)
Features
Bug Fixes

v11.1.0

Compare Source

Features
  • update TS types to allowUint8Array subtypes for buffer option (#​865) (a5231e7)

v11.0.5

Compare Source

Bug Fixes

v11.0.4

Compare Source

Bug Fixes

v11.0.3

Compare Source

Bug Fixes

v11.0.2

Compare Source

Bug Fixes

v11.0.1

Compare Source

Bug Fixes

v11.0.0

Compare Source

⚠ BREAKING CHANGES
  • refactor v1 internal state and options logic (#​780)
  • refactor v7 internal state and options logic, fixes #​764 (#​779)
  • Port to TypeScript, closes #​762 (#​763)
  • update node support matrix (only support node 16-20) (#​750)
Features
Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested review from a team as code owners April 23, 2026 03:55
@product-auto-label product-auto-label Bot added samples Issues that are directly related to samples. api: aiplatform Issues related to the AI Platform API. api: appengine Issues related to the App Engine Admin API API. api: auth api: automl Issues related to the AutoML API. api: cloudasset Issues related to the Cloud Asset Inventory API. api: cloudfunctions Issues related to the Cloud Run functions API. api: compute Issues related to the Compute Engine API. api: contactcenterinsights Issues related to the Contact Center AI Insights API. api: containeranalysis Issues related to the Container Analysis API. api: datacatalog Issues related to the Data Catalog API. api: dataproc Issues related to the Dataproc API. labels Apr 23, 2026
@product-auto-label product-auto-label Bot added api: datastore Issues related to the Datastore API. api: dialogflow Issues related to the Dialogflow API. api: discoveryengine Issues related to the Discovery Engine API API. api: dlp Issues related to the Sensitive Data Protection API. api: documentai Issues related to the Document AI API. api: eventarc Issues related to the Eventarc API. api: genai api: language Issues related to the Cloud Natural Language API API. api: tasks Issues related to the Tasks API API. asset: pattern DEE Asset tagging - Pattern. labels Apr 23, 2026
@dpebot
Copy link
Copy Markdown
Contributor

dpebot commented Apr 23, 2026

/gcbrun

@trusted-contributions-gcf trusted-contributions-gcf Bot added kokoro:force-run Add this label to force Kokoro to re-run the tests. actions:force-run labels Apr 23, 2026
Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the uuid dependency to version 14 across multiple packages. The review feedback identifies that uuid v14 requires Node.js >= 20.0.0 and is ESM-only, which creates critical incompatibilities with the current engine specifications and CommonJS require() calls in several packages. Additionally, the @types/uuid devDependency is now redundant and should be removed.

Comment thread storage/package.json
"@google-cloud/storage": "^7.19.0",
"node-fetch": "^2.6.7",
"uuid": "^8.0.0",
"uuid": "^14.0.0",
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

This update to uuid v14 is incompatible with the declared Node.js version support (>=12 on line 7). uuid v14 requires Node.js >= 20.0.0. Furthermore, the removal of CommonJS support in uuid v12+ will break any require('uuid') calls in this package, as it is not configured as an ES module. Since this is a production dependency, this change is critical.

"chai": "^4.5.0",
"mocha": "^10.0.0",
"uuid": "^10.0.0",
"uuid": "^14.0.0",
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

Updating to uuid v14 introduces significant breaking changes that are incompatible with the current project configuration:

  1. Node.js Version: uuid v14 requires Node.js >= 20.0.0 (due to its dependency on the global crypto object). This conflicts with the engines requirement of >=16.0.0 specified on line 7.
  2. ESM Requirement: uuid dropped CommonJS support in v12. Since this package does not specify "type": "module", it likely uses require(), which will fail at runtime with this version.

If this update is necessary for security, the project's Node.js requirement and module type should be updated accordingly.

"proxyquire": "^2.1.3",
"supertest": "^7.0.0",
"uuid": "^10.0.0"
"uuid": "^14.0.0"
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

In addition to the Node.js 20+ and ESM requirements of uuid v14, note that @types/uuid (line 22) is now redundant. Since v11, uuid includes its own TypeScript definitions. You should remove the @types/uuid dependency to avoid potential conflicts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

actions:force-run api: aiplatform Issues related to the AI Platform API. api: appengine Issues related to the App Engine Admin API API. api: auth api: automl Issues related to the AutoML API. api: cloudasset Issues related to the Cloud Asset Inventory API. api: cloudfunctions Issues related to the Cloud Run functions API. api: compute Issues related to the Compute Engine API. api: contactcenterinsights Issues related to the Contact Center AI Insights API. api: containeranalysis Issues related to the Container Analysis API. api: datacatalog Issues related to the Data Catalog API. api: dataproc Issues related to the Dataproc API. api: datastore Issues related to the Datastore API. api: dialogflow Issues related to the Dialogflow API. api: discoveryengine Issues related to the Discovery Engine API API. api: dlp Issues related to the Sensitive Data Protection API. api: documentai Issues related to the Document AI API. api: eventarc Issues related to the Eventarc API. api: genai api: language Issues related to the Cloud Natural Language API API. api: tasks Issues related to the Tasks API API. asset: pattern DEE Asset tagging - Pattern. kokoro:force-run Add this label to force Kokoro to re-run the tests. major samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants