{"api_version":"v1","generated_at":"2026-10-07T02:55:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-xerces-c-883e2710f35e","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Xerces-C","next_cursor":null,"observations":[{"affected":"3.0.0 < 3.2.5","affected_versions_present":true,"cve_id":"CVE-2024-23807","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-23807","fixed":"3.2.3","last_modified":"2026-01-22T04:55:53.687Z","patch_url":"https://github.com/apache/xerces-c/pull/54","primary_source":"","published":"2024-02-28T13:50:39.904Z"},{"affected":"3.0.0 to 3.2.2","affected_versions_present":true,"cve_id":"CVE-2018-1311","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1311","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-04T18:14:14.531Z","patch_url":"https://www.oracle.com/security-alerts/cpujan2022.html","primary_source":"","published":"2019-12-18T00:00:00.000Z"},{"affected":"< 3.2.1","affected_versions_present":true,"cve_id":"CVE-2017-12627","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12627","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T01:15:50.981Z","patch_url":"","primary_source":"","published":"2018-03-01T14:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
