High severity7.5NVD Advisory· Published May 7, 2021· Updated Jun 17, 2026
CVE-2021-29499
CVE-2021-29499
Description
SIF is an open source implementation of the Singularity Container Image Format. The siftool new command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the github.com/satori/go.uuid module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the ID field is generated using a version of github.com/satori/go.uuid that is not vulnerable to this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/sylabs/sifGo | < 1.2.3 | 1.2.3 |
Affected products
3- cpe:2.3:a:sylabs:singularity_image_format:*:*:*:*:*:*:*:*Range: <1.2.3
Patches
Vulnerability mechanics
References
5- github.com/sylabs/sif/security/advisories/GHSA-4gh8-x3vv-phhgnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-4gh8-x3vv-phhgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-29499ghsaADVISORY
- github.com/satori/go.uuid/issues/73ghsaWEB
- github.com/sylabs/sif/commit/193962882122abf85ff5f5bcc86404933e71c07dghsaWEB
News mentions
0No linked articles in our index yet.