{"api_version":"v1","generated_at":"2026-10-07T03:25:00+00:00","product":{"cve_count":6,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-authlib-joserfc-1025d53fa647","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"joserfc","next_cursor":null,"observations":[{"affected":"< 1.7.3","affected_versions_present":true,"cve_id":"CVE-2026-75509","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75509","fixed":"1.7.3.","last_modified":"2026-08-25T16:42:19.769Z","patch_url":"https://github.com/authlib/joserfc/security/advisories/GHSA-r74j-q665-7rpj","primary_source":"","published":"2026-08-24T20:08:07.088Z"},{"affected":"< 1.7.2","affected_versions_present":true,"cve_id":"CVE-2026-62995","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62995","fixed":"1.7.2.","last_modified":"2026-07-30T14:32:13.148Z","patch_url":"https://github.com/authlib/joserfc/security/advisories/GHSA-5jhw-7jv7-qcqq","primary_source":"","published":"2026-07-29T18:27:06.518Z"},{"affected":"< 1.6.8","affected_versions_present":true,"cve_id":"CVE-2026-49852","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49852","fixed":"1.6.8.","last_modified":"2026-07-20T14:58:41.701Z","patch_url":"https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh","primary_source":"","published":"2026-07-17T19:14:58.019Z"},{"affected":"< 1.6.7","affected_versions_present":true,"cve_id":"CVE-2026-48990","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48990","fixed":"1.6.7.","last_modified":"2026-06-18T12:51:59.900Z","patch_url":"https://github.com/authlib/joserfc/security/advisories/GHSA-wphv-vfrh-23q5","primary_source":"","published":"2026-06-17T21:08:10.534Z"},{"affected":"<= 1.6.2","affected_versions_present":true,"cve_id":"CVE-2026-27932","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27932","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-04T21:20:55.097Z","patch_url":"https://github.com/authlib/joserfc/commit/696a9611ab982c45ee2190ed79ca8e1d8e09398f","primary_source":"","published":"2026-03-03T22:48:21.306Z"},{"affected":">= 1.3.3, < 1.3.5; >= 1.4.0, < 1.4.2","affected_versions_present":true,"cve_id":"CVE-2025-65015","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-65015","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-19T17:12:04.336Z","patch_url":"https://github.com/authlib/joserfc/commit/63932f169d924caffafa761af2122b82059017f7","primary_source":"","published":"2025-11-18T23:07:44.328Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"authlib"}}
