{"api_version":"v1","generated_at":"2026-10-07T21:40:00+00:00","product":{"cve_count":7,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-cloud-foundry-uaa-0e0b3a3f63cc","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/uaa","name":"UAA","next_cursor":null,"observations":[{"affected":"UAA: 4.5.0 \u2264 79.6.0; cf-deployment: \u2264 60.4.0","affected_versions_present":true,"cve_id":"CVE-2026-59357","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59357","fixed":"UAA: 79.7.0; cf-deployment: 60.5.0","last_modified":"2026-10-06T11:49:21.187Z","patch_url":"https://www.cloudfoundry.org/blog/cve-2026-59357-self-uaa-oidc-configuration-allows-jwt-injection-to-establish-unauthorized-sessions/","primary_source":"","published":"2026-10-06T07:06:18.486Z"},{"affected":"UAA: 3.7.0 \u2264 79.6.0; cf-deployment: \u2264 60.4.0","affected_versions_present":true,"cve_id":"CVE-2026-59358","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59358","fixed":"UAA: 79.7.0; cf-deployment: 60.5.0","last_modified":"2026-10-06T14:34:25.951Z","patch_url":"https://www.cloudfoundry.org/blog/cve-2026-59358-uaa-oauth-token-endpoint-vulnerability-allows-user-access-token-reuse-for-client_credentials-grant-type/","primary_source":"","published":"2026-10-06T06:54:10.861Z"},{"affected":"UAA: < 78.16.0; cf-deployment: < 57.0.0","affected_versions_present":true,"cve_id":"CVE-2026-59335","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59335","fixed":"UAA: 78.16.0; cf-deployment: 57.0.0","last_modified":"2026-08-25T13:09:07.719Z","patch_url":"https://www.cloudfoundry.org/blog/cve-2026-59335-uaa-case-insensitive-check-bypass/","primary_source":"","published":"2026-08-25T11:05:11.166Z"},{"affected":"2.0.0 < 78.14.0; 0.0.0 < 57.0.0","affected_versions_present":true,"cve_id":"CVE-2026-41005","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41005","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-13T03:55:30.398Z","patch_url":"","primary_source":"","published":"2026-06-11T20:03:22.525Z"},{"affected":"v77.21.0 < v77.32.0; v45.1.0 \u2264 v48.11.0","affected_versions_present":true,"cve_id":"CVE-2025-22246","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-22246","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-13T13:49:09.193Z","patch_url":"https://www.cloudfoundry.org/blog/cve-2025-22246-uaa-private-key-exposure/","primary_source":"","published":"2025-05-13T05:14:40.968Z"},{"affected":"unspecified < v74.14.0","affected_versions_present":true,"cve_id":"CVE-2020-5402","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-5402","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T17:03:33.297Z","patch_url":"","primary_source":"","published":"2020-02-27T19:30:24.167Z"},{"affected":"all versions < 4.23.0; all versions < 64.0","affected_versions_present":true,"cve_id":"CVE-2018-15761","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-15761","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T00:46:20.654Z","patch_url":"","primary_source":"","published":"2018-11-19T14:00:00.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Cloud Foundry"}}
