{"api_version":"v1","generated_at":"2026-10-04T12:00:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-httpcomponents-client-a568bac82212","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache HttpComponents Client","next_cursor":null,"observations":[{"affected":"Apache HttpComponents Client: 5.4-alpha \u2264 5.6.3","affected_versions_present":true,"cve_id":"CVE-2026-71290","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71290","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T03:55:24.916Z","patch_url":"","primary_source":"","published":"2026-08-11T20:33:56.947Z"},{"affected":"5.0-alpha \u2264 5.6.2","affected_versions_present":true,"cve_id":"CVE-2026-64607","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-64607","fixed":"It is recommended that existing users of Red Hat OpenShift Developer Tools - OpenShift Jenkins 4.12 upgrade to the latest. This image uses java-21-openjdk as the default JDK. java-25-openjdk is not available in rhel8 images. java-17-openjdk is removed.","last_modified":"2026-08-13T16:18:20.395Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-64607","primary_source":"","published":"2026-07-31T10:12:18.035Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"Apache Software Foundation"}}
