Skip to content

Security: uuid@11.x has vulnerability CVE-2026-41907 (SNYK-JS-UUID-16133035) — fix available in uuid@14+ #16459

@brent-brookfieldsg

Description

@brent-brookfieldsg

Summary

uuid@11.x is a transitive dependency of payload, @payloadcms/next, and @payloadcms/ui. A patched version (uuid@14.0.0+) is available but Payload has not yet updated to it.

Vulnerability details

  • Snyk ID: SNYK-JS-UUID-16133035
  • CVE: CVE-2026-41907
  • Package: uuid@11.1.0 (current in Payload 3.84.1)
  • Type: Improper Validation of Specified Index, Position, or Offset in Input
  • Fix: Upgrade to uuid >= 14.0.0

Dependency path

payload@3.84.1 → uuid@11.1.0
@payloadcms/next@3.84.1 → uuid@11.1.0
@payloadcms/ui@3.84.1 → uuid@11.1.0

Request

Please update the uuid dependency to >=14.0.0 in the affected Payload packages. Downstream users cannot safely force-override this without risking breaking Payload's internal ID generation.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions