{"id":"CVE-2015-8851","title":"node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.","summary":"node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-331"],"vendor":"node-uuid_project","product":"node-uuid","affected":["node-uuid < 1.4.4"],"patched":["node-uuid 1.4.4"],"published":"2020-01-30","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:16:59.953","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-8851","references":[{"url":"http://www.openwall.com/lists/oss-security/2016/04/13/8","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1327056","label":"secalert@redhat.com"},{"url":"https://github.com/broofa/node-uuid/commit/672f3834ed02c798aa021c618d0a5666c8da000d","label":"secalert@redhat.com"},{"url":"https://nodesecurity.io/advisories/93","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2016/04/13/8","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1327056","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/broofa/node-uuid/commit/672f3834ed02c798aa021c618d0a5666c8da000d","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nodesecurity.io/advisories/93","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.02257,"epssPercentile":0.82426,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T20:05:58.299008Z"},"ingestedAt":"2026-10-07T20:46:46.998Z","slug":"CVE-2015-8851","body":"## Overview\n\nnode-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.\n\n## Affected\n\n- `node-uuid < 1.4.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `node-uuid 1.4.4`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}