{"api_version":"v1","generated_at":"2026-10-08T09:45:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-akuity-kargo-d6ca1693c8e2","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/kargo","name":"kargo","next_cursor":null,"observations":[{"affected":"< 1.7.10; >= 1.8.0-rc.1, < 1.8.13; >= 1.9.0-rc.1, < 1.9.8; >= 1.10.0-rc.1, < 1.10.2","affected_versions_present":true,"cve_id":"CVE-2026-42350","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42350","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-12T18:31:37.913Z","patch_url":"","primary_source":"","published":"2026-05-08T22:35:30.155Z"},{"affected":">= 1.4.0, < 1.6.4; >= 1.7.0-rc.1, < 1.7.9; >= 1.8.0-rc.1, < 1.8.12; >= 1.9.0-rc.1, < 1.9.5","affected_versions_present":true,"cve_id":"CVE-2026-32828","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32828","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-25T14:38:54.598Z","patch_url":"https://github.com/akuity/kargo/commit/fd25620c2473ed19bec4be4d0f181287ef0f0391","primary_source":"","published":"2026-03-20T00:39:25.548Z"},{"affected":">= 1.9.0-rc.1, < 1.9.3; >= 1.8.0-rc.1, < 1.8.11; >= 1.7.0, < 1.7.8","affected_versions_present":true,"cve_id":"CVE-2026-27112","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27112","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-24T18:43:40.423Z","patch_url":"https://github.com/akuity/kargo/commit/155c6852ffbffa2902f18e6c7add91a846e8d344","primary_source":"","published":"2026-02-20T21:22:56.719Z"},{"affected":">= 1.9.0, < 1.9.3","affected_versions_present":true,"cve_id":"CVE-2026-27111","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27111","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-24T18:46:03.564Z","patch_url":"https://github.com/akuity/kargo/commit/833314cad5513d48d89431493325ae44c1324a49","primary_source":"","published":"2026-02-20T21:17:07.383Z"},{"affected":"< 1.6.3; >= 1.7.0, < 1.7.7; <= 1.8.0, < 1.8.7","affected_versions_present":true,"cve_id":"CVE-2026-24748","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24748","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-28T21:15:14.453Z","patch_url":"https://github.com/akuity/kargo/commit/23646eaefb449a6cc2e76a8033e8a57f71369772","primary_source":"","published":"2026-01-27T21:23:53.890Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"akuity"}}
