{"api_version":"v1","generated_at":"2026-10-08T12:40:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-astral-sh-uv-caf708ebedaa","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/uv","name":"uv","next_cursor":null,"observations":[{"affected":"uv: >= 0.12.7, < 0.12.18","affected_versions_present":true,"cve_id":"CVE-2026-104843","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104843","fixed":"0.12.18.","last_modified":"2026-10-02T16:00:53.033Z","patch_url":"https://github.com/astral-sh/uv/security/advisories/GHSA-2cv4-cqwr-gwf7","primary_source":"","published":"2026-10-02T15:29:15.517Z"},{"affected":"< 0.9.6","affected_versions_present":true,"cve_id":"CVE-2025-13327","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13327","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-18T03:20:18.936Z","patch_url":"https://github.com/astral-sh/uv/commit/da659fee4898a73dbc75070f3e82d49f745e4628","primary_source":"","published":"2026-02-27T07:30:20.131Z"},{"affected":"< 0.8.6","affected_versions_present":true,"cve_id":"CVE-2025-54368","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54368","fixed":"0.8.6.","last_modified":"2025-08-08T17:32:18.259Z","patch_url":"https://github.com/astral-sh/uv/security/advisories/GHSA-8qf3-x8v5-2pj8","primary_source":"","published":"2025-08-08T00:00:39.001Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"astral-sh"}}
