{"api_version":"v1","generated_at":"2026-10-07T16:45:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-asterisk-asterisk-1a040c3ab88e","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/asterisk","name":"Asterisk","next_cursor":null,"observations":[{"affected":"< 23.2.2; < 22.8.2; < 21.12.1; < 20.18.2; < 20.7-cert9","affected_versions_present":true,"cve_id":"CVE-2026-23741","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23741","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-06T17:26:22.216Z","patch_url":"","primary_source":"","published":"2026-02-06T16:47:19.611Z"},{"affected":"< 23.2.2; < 22.8.2; < 21.12.1; < 20.18.2; < 20.7-cert9","affected_versions_present":true,"cve_id":"CVE-2026-23740","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23740","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-06T19:11:55.655Z","patch_url":"","primary_source":"","published":"2026-02-06T16:43:41.330Z"},{"affected":"< 23.2.2; < 22.8.2; < 21.12.1; < 20.18.2; < 20.7-cert9","affected_versions_present":true,"cve_id":"CVE-2026-23739","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23739","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-06T17:37:22.223Z","patch_url":"","primary_source":"","published":"2026-02-06T16:42:25.816Z"},{"affected":"< 23.2.2; < 22.8.2; < 21.12.1; < 20.18.2; < 20.7-cert9","affected_versions_present":true,"cve_id":"CVE-2026-23738","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23738","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-06T17:44:20.480Z","patch_url":"","primary_source":"","published":"2026-02-06T16:41:43.769Z"},{"affected":"Asterisk <=18.26.2; Asterisk <= 20.15.0; Asterisk <= 21.10.0; Asterisk <= 22.5.0","affected_versions_present":true,"cve_id":"CVE-2025-1131","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-1131","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T17:48:19.381Z","patch_url":"","primary_source":"","published":"2025-09-23T04:31:02.784Z"},{"affected":"< 22.5.2; < 21.10.2; < 20.15.2","affected_versions_present":true,"cve_id":"CVE-2025-57767","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-57767","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-08-28T17:12:35.539Z","patch_url":"https://github.com/asterisk/asterisk/pull/1407","primary_source":"","published":"2025-08-28T15:33:00.087Z"},{"affected":"< 18.26.4; < 18.9-cert17","affected_versions_present":true,"cve_id":"CVE-2025-54995","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54995","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T17:45:15.011Z","patch_url":"https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9","primary_source":"","published":"2025-08-28T15:08:04.468Z"},{"affected":"< 18.26.3; >= 20.00.0, < 20.15.1; >= 21.00.0, < 21.10.1; >= 22.00.0, < 22.5.1; >= 20.7-cert6, < 20.7-cert7","affected_versions_present":true,"cve_id":"CVE-2025-49832","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49832","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-08-01T18:29:18.330Z","patch_url":"","primary_source":"","published":"2025-08-01T17:57:29.933Z"},{"affected":"< 18.9-cert14; >= 18.10, < 18.26.2; >= 20.0, < 20.7-cert5; >= 20.8, < 20.14.1; >= 21.0, < 21.9.1; >= 22.0, < 22.4.1","affected_versions_present":true,"cve_id":"CVE-2025-47780","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47780","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T20:04:38.254Z","patch_url":"","primary_source":"","published":"2025-05-22T16:56:28.937Z"},{"affected":"< 18.9-cert14; >= 18.10, < 18.26.2; >= 20.0, < 20.7-cert5; >= 20.8, < 20.14.1; >= 21.0, < 21.9.1; >= 22.0, < 22.4.1","affected_versions_present":true,"cve_id":"CVE-2025-47779","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47779","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-03T20:04:36.858Z","patch_url":"","primary_source":"","published":"2025-05-22T16:54:26.314Z"},{"affected":"< 18.24.3; >= 19.0.0, < 20.9.3; >= 21.0.0, < 21.4.3; < 18.9-cert12; >= 19.0, < 20.7-cert2","affected_versions_present":true,"cve_id":"CVE-2024-42491","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42491","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T22:04:56.291Z","patch_url":"https://github.com/asterisk/asterisk/commit/42a2f4ccfa2c7062a15063e765916b3332e34cc4","primary_source":"","published":"2024-09-05T17:17:56.961Z"},{"affected":"< 18.24.2; >= 19.0.0, < 20.9.2; >= 21.0.0, < 21.4.2; < 18.9-cert11; >= 19.0, < 20.7-cert2","affected_versions_present":true,"cve_id":"CVE-2024-42365","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42365","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-03T22:04:48.935Z","patch_url":"https://github.com/asterisk/asterisk/commit/42a2f4ccfa2c7062a15063e765916b3332e34cc4","primary_source":"","published":"2024-08-08T16:29:07.436Z"},{"affected":"= 21.3.0; = 20.8.0; = 18.23.0","affected_versions_present":true,"cve_id":"CVE-2024-35190","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-35190","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T03:07:46.821Z","patch_url":"https://github.com/asterisk/asterisk/pull/600","primary_source":"","published":"2024-05-17T16:55:41.346Z"},{"affected":"< 18.20.1; >= 19.0.0, < 20.5.1; = 21.0.0; < 18.9-cert6","affected_versions_present":true,"cve_id":"CVE-2023-49786","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49786","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:18:55.224Z","patch_url":"https://github.com/asterisk/asterisk/commit/d7d7764cb07c8a1872804321302ef93bf62cba05","primary_source":"","published":"2023-12-14T19:47:46.306Z"},{"affected":"<= 18.20.0; >= 19.0.0, <= 20.5.0; = 21.0.0; <= 18.9-cert5","affected_versions_present":true,"cve_id":"CVE-2023-37457","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37457","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:01:26.636Z","patch_url":"https://github.com/asterisk/asterisk/commit/a1ca0268254374b515fa5992f01340f7717113fa","primary_source":"","published":"2023-12-14T19:43:30.945Z"},{"affected":"< 18.20.1; >= 19.0.0, < 20.5.1; = 21.0.0; < 18.9-cert6","affected_versions_present":true,"cve_id":"CVE-2023-49294","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49294","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:18:40.277Z","patch_url":"https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5","primary_source":"","published":"2023-12-14T19:40:46.157Z"},{"affected":"All 1.6.1 versions","affected_versions_present":true,"cve_id":"CVE-2009-3723","cve_url":"https://cve.blacktree.nl/cve/CVE-2009-3723","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-07T06:38:30.400Z","patch_url":"","primary_source":"","published":"2019-10-29T12:42:08.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Asterisk"}}
