{"api_version":"v1","generated_at":"2026-10-06T06:10:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-poi-ffb8ab11bbd2","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache POI","next_cursor":null,"observations":[{"affected":"< 5.4.0","affected_versions_present":true,"cve_id":"CVE-2025-31672","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-31672","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-23T13:11:07.642Z","patch_url":"","primary_source":"","published":"2025-04-09T11:59:33.900Z"},{"affected":"< 3.17","affected_versions_present":true,"cve_id":"CVE-2017-12626","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12626","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T17:54:38.163Z","patch_url":"","primary_source":"","published":"2018-01-29T17:00:00.000Z"},{"affected":"before 3.15","affected_versions_present":true,"cve_id":"CVE-2017-5644","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5644","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T15:11:47.262Z","patch_url":"","primary_source":"","published":"2017-03-24T14:00:00.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Apache Software Foundation"}}
