{"api_version":"v1","generated_at":"2026-10-06T15:45:00+00:00","product":{"cve_count":15,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-karaf-a33b3858946f","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Karaf","next_cursor":null,"observations":[{"affected":"Apache Karaf: < 4.4.12","affected_versions_present":true,"cve_id":"CVE-2026-92142","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92142","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T14:24:03.845Z","patch_url":"","primary_source":"","published":"2026-09-29T08:40:07.961Z"},{"affected":"Apache Karaf: < 4.4.12","affected_versions_present":true,"cve_id":"CVE-2026-91085","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91085","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T14:18:12.957Z","patch_url":"","primary_source":"","published":"2026-09-29T08:39:33.209Z"},{"affected":"Apache Karaf: < 4.4.12","affected_versions_present":true,"cve_id":"CVE-2026-91048","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91048","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T14:13:30.717Z","patch_url":"","primary_source":"","published":"2026-09-29T08:34:47.193Z"},{"affected":"Apache Karaf: < 4.4.12","affected_versions_present":true,"cve_id":"CVE-2026-91012","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91012","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T14:10:47.838Z","patch_url":"","primary_source":"","published":"2026-09-29T08:34:11.409Z"},{"affected":"Apache Karaf: < 4.4.12","affected_versions_present":true,"cve_id":"CVE-2026-91006","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-91006","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-29T21:03:21.368Z","patch_url":"","primary_source":"","published":"2026-09-28T10:44:32.652Z"},{"affected":"Apache Karaf: < 4.4.12","affected_versions_present":true,"cve_id":"CVE-2026-90979","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90979","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-30T19:53:57.685Z","patch_url":"","primary_source":"","published":"2026-09-28T09:34:33.253Z"},{"affected":"Apache Karaf: < 4.4.11","affected_versions_present":true,"cve_id":"CVE-2026-92230","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92230","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-18T13:33:04.842Z","patch_url":"","primary_source":"","published":"2026-09-17T18:38:29.556Z"},{"affected":"< 2.12.0","affected_versions_present":true,"cve_id":"CVE-2026-24656","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24656","fixed":"2.12.0","last_modified":"2026-01-26T18:35:51.514Z","patch_url":"https://lists.apache.org/thread/dc5wmdn6hyc992olntkl75kk04ndzx34","primary_source":"","published":"2026-01-26T09:41:24.356Z"},{"affected":"4.4.0 < 4.4.2; < 4.3.8","affected_versions_present":true,"cve_id":"CVE-2022-40145","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-40145","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-15T18:03:47.618Z","patch_url":"","primary_source":"","published":"2022-12-21T15:23:42.847Z"},{"affected":"Apache Karaf < 4.2.15","affected_versions_present":true,"cve_id":"CVE-2022-22932","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-22932","fixed":"Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.11.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.11/","last_modified":"2024-08-03T03:28:42.479Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-22932","primary_source":"","published":"2022-01-26T11:10:12.000Z"},{"affected":"Apache Karaf < 4.3.6","affected_versions_present":true,"cve_id":"CVE-2021-41766","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41766","fixed":"Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. Installation instructions are available from the Fuse 7.11.0 product documentation page: https://access.redhat.com/documentation/en-us/red_hat_fuse/7.11/","last_modified":"2024-08-04T03:15:29.312Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-41766","primary_source":"","published":"2022-01-26T11:10:11.000Z"},{"affected":"Any Apache Karaf version prior to 4.1.7 and 4.2.2","affected_versions_present":true,"cve_id":"CVE-2018-11788","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11788","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T08:17:09.240Z","patch_url":"","primary_source":"","published":"2019-01-07T16:00:00.000Z"},{"affected":"prior to 3.0.9; 4.0.x prior to 4.0.9; 4.1.x prior to 4.1.1","affected_versions_present":true,"cve_id":"CVE-2018-11787","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11787","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T02:16:58.807Z","patch_url":"http://karaf.apache.org/security/cve-2018-11787.txt","primary_source":"","published":"2018-09-18T14:00:00.000Z"},{"affected":"prior to 4.2.0 release","affected_versions_present":true,"cve_id":"CVE-2018-11786","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-11786","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T02:12:17.084Z","patch_url":"https://issues.apache.org/jira/browse/KARAF-5427","primary_source":"","published":"2018-09-18T14:00:00.000Z"},{"affected":"prior to 4.0.8","affected_versions_present":true,"cve_id":"CVE-2016-8750","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-8750","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T00:36:15.735Z","patch_url":"https://karaf.apache.org/security/cve-2016-8750.txt","primary_source":"","published":"2018-02-19T15:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
