{"api_version":"v1","generated_at":"2026-10-08T20:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-agronholm-cbor2-0e6e1ba83d7a","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cbor2","name":"cbor2","next_cursor":null,"observations":[{"affected":"< 5.9.0","affected_versions_present":true,"cve_id":"CVE-2026-26209","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26209","fixed":"For more information visit https://access.redhat.com/errata/RHSA-2026:19724","last_modified":"2026-03-24T18:35:35.486Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-26209","primary_source":"","published":"2026-03-23T18:53:10.268Z"},{"affected":">= 3.0.0, < 5.8.0","affected_versions_present":true,"cve_id":"CVE-2025-68131","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68131","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-02T14:37:55.705Z","patch_url":"https://github.com/agronholm/cbor2/pull/268","primary_source":"","published":"2025-12-31T01:15:36.827Z"},{"affected":">= 5.5.1, < 5.6.2","affected_versions_present":true,"cve_id":"CVE-2024-26134","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26134","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:41:03.627Z","patch_url":"https://github.com/agronholm/cbor2/commit/4de6991ba29bf2290d7b9d83525eda7d021873df","primary_source":"","published":"2024-02-19T22:13:47.173Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"agronholm"}}
