CVE-2026-41907

Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.18.27 security, enhancement & bug fix update

Description

A flaw was found in uuid. The library's versions v3, v5, and v6 do not adequately check the size of external memory buffers provided by applications. This oversight allows the library to write data beyond the designated buffer limits without signaling an error. Such out-of-bounds writes can lead to data corruption, unintended information disclosure, or disrupt application availability.

Metrics

Severity
high
no public PoC known
8.1
Source: nvd-v4
28.1 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-18 18:22 UTC
CWE-823, CWE-787

Weakness classes (CWE)

  • CWE-823Base

    Use of Out-of-range Pointer Offset

    The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.

    cwe.mitre.org →
  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    golang1.25.0

  • go-jose_project

    go-jose3.0.0 – 3.0.5

  • go-jose_project

    go-jose4.0.0 – 4.1.4

  • golang

    go1.25.0 – 1.25.6

  • golang

    go1.24.12

  • golang

    net0.55.0

  • grpc

    grpc1.79.3

  • IBM

    App Connect EnterpriseCD 13.4.0

  • IBM

    App Connect EnterpriseLTS 12.0.26

  • IBM

    App Connect EnterpriseLTS 13.4.0

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • nodeca

    js-yaml4.0.0 – 4.2.0

  • nodeca

    js-yaml3.15.0

References & sources

Linked CVEs

Show 17 more CVEs
IDCVE-2026-41907