{"api_version":"v1","generated_at":"2026-10-07T15:50:00+00:00","product":{"cve_count":11,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-aces-loris-bac71449ada2","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/loris","name":"Loris","next_cursor":null,"observations":[{"affected":"< 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-39985","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39985","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-10T14:07:40.047Z","patch_url":"https://github.com/aces/Loris/commit/f57f54b42a076bf53ba86e20d4dbf37f63538f58","primary_source":"","published":"2026-04-09T17:08:49.668Z"},{"affected":">= 24.0.0, < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-35446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35446","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-08T20:13:54.835Z","patch_url":"https://github.com/aces/Loris/security/advisories/GHSA-47jj-7xfg-8759","primary_source":"","published":"2026-04-08T18:28:30.405Z"},{"affected":">= 15.10, < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-35403","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35403","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-10T20:42:38.101Z","patch_url":"https://github.com/aces/Loris/security/advisories/GHSA-776p-5pwh-vc8p","primary_source":"","published":"2026-04-08T18:27:17.221Z"},{"affected":">= 20.0.0, < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-35400","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35400","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T19:52:33.071Z","patch_url":"","primary_source":"","published":"2026-04-08T18:26:09.890Z"},{"affected":">= , < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-35169","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35169","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-09T14:21:17.788Z","patch_url":"","primary_source":"","published":"2026-04-08T18:24:27.757Z"},{"affected":">= 21.0.0, < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-35165","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35165","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-08T20:13:29.831Z","patch_url":"https://github.com/aces/Loris/security/advisories/GHSA-qp6x-qfx7-54wp","primary_source":"","published":"2026-04-08T18:23:34.101Z"},{"affected":">= 16.1.0, < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-34985","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34985","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-10T20:41:48.430Z","patch_url":"","primary_source":"","published":"2026-04-08T18:22:09.927Z"},{"affected":">= 20.0.0, < 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-34392","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34392","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-09T14:23:46.526Z","patch_url":"https://github.com/aces/Loris/security/advisories/GHSA-rfj5-58hv-wc5f","primary_source":"","published":"2026-04-08T17:57:35.927Z"},{"affected":"< 27.0.3; >= 28.0.0, < 28.0.1","affected_versions_present":true,"cve_id":"CVE-2026-33350","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33350","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T19:24:05.846Z","patch_url":"","primary_source":"","published":"2026-04-08T17:47:32.566Z"},{"affected":">= 24.0.0, < 26.0.5; >= 27.0.0, < 27.0.2","affected_versions_present":true,"cve_id":"CVE-2026-26985","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26985","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-25T21:39:45.355Z","patch_url":"","primary_source":"","published":"2026-02-25T21:26:00.201Z"},{"affected":"< 26.0.5; >= 27.0.0, < 27.0.2","affected_versions_present":true,"cve_id":"CVE-2026-26984","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26984","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-25T21:42:13.721Z","patch_url":"","primary_source":"","published":"2026-02-25T21:15:54.790Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"aces"}}
