{"api_version":"v1","generated_at":"2026-10-06T01:25:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-cloudreve-cloudreve-9e1cecdc44bc","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/cloudreve","name":"Cloudreve","next_cursor":null,"observations":[{"affected":"cloudreve: < 4.16.1","affected_versions_present":true,"cve_id":"CVE-2026-101056","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101056","fixed":"cloudreve: 4.16.1","last_modified":"2026-09-28T13:17:06.855Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w","primary_source":"","published":"2026-09-27T17:02:38.060Z"},{"affected":"cloudreve: < 4.16.1","affected_versions_present":true,"cve_id":"CVE-2026-101051","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101051","fixed":"cloudreve: 4.16.1","last_modified":"2026-09-28T14:06:18.432Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8j7-39hp-8x59","primary_source":"","published":"2026-09-27T17:02:37.358Z"},{"affected":"cloudreve: < 4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-101048","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101048","fixed":"cloudreve: 4.17.0","last_modified":"2026-09-30T15:30:30.176Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-v6w6-358x-2433","primary_source":"","published":"2026-09-27T17:02:36.546Z"},{"affected":"cloudreve: < 4.18.0","affected_versions_present":true,"cve_id":"CVE-2026-77637","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77637","fixed":"4.18.0.","last_modified":"2026-09-22T17:43:54.828Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w89x-c962-c44g","primary_source":"","published":"2026-09-22T15:30:59.216Z"},{"affected":"cloudreve: < 4.18.0","affected_versions_present":true,"cve_id":"CVE-2026-77633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77633","fixed":"4.18.0.","last_modified":"2026-09-25T23:38:53.232Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-xj3h-wwxq-gfcj","primary_source":"","published":"2026-09-22T15:28:56.700Z"},{"affected":"cloudreve: < 4.18.0","affected_versions_present":true,"cve_id":"CVE-2026-79913","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-79913","fixed":"4.18.0.","last_modified":"2026-09-22T17:44:01.258Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-jvh5-97xg-v99f","primary_source":"","published":"2026-09-22T15:24:33.456Z"},{"affected":"< 4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-62323","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62323","fixed":"4.17.0.","last_modified":"2026-07-31T19:28:19.622Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-c3jm-gv5r-9wcp","primary_source":"","published":"2026-07-31T03:43:14.900Z"},{"affected":"< 4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-55502","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55502","fixed":"4.17.0.","last_modified":"2026-07-31T11:09:00.719Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-hq88-5x99-x3gf","primary_source":"","published":"2026-07-31T03:35:59.389Z"},{"affected":"< 4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-55499","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55499","fixed":"4.17.0.","last_modified":"2026-07-31T23:15:27.840Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w8x7-h2px-xmq8","primary_source":"","published":"2026-07-31T03:34:33.206Z"},{"affected":"< 4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-55497","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55497","fixed":"4.17.0.","last_modified":"2026-07-31T15:58:48.793Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-g9j2-8w95-3vwv","primary_source":"","published":"2026-07-31T03:28:59.171Z"},{"affected":"4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-55496","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55496","fixed":"4.17.0.","last_modified":"2026-07-31T14:02:34.248Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-8r7f-r8hj-r3rv","primary_source":"","published":"2026-07-31T03:23:33.099Z"},{"affected":"< 4.17.0","affected_versions_present":true,"cve_id":"CVE-2026-55495","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55495","fixed":"4.17.0.","last_modified":"2026-07-31T19:27:00.216Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-49h3-cwhj-4737","primary_source":"","published":"2026-07-31T02:58:14.080Z"},{"affected":">= 4.12.0, < 4.16.1","affected_versions_present":true,"cve_id":"CVE-2026-54560","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54560","fixed":"4.16.1.","last_modified":"2026-07-15T15:16:35.699Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vgj4-345g-jcf8","primary_source":"","published":"2026-07-15T14:40:24.765Z"},{"affected":"< 4.16.1","affected_versions_present":true,"cve_id":"CVE-2026-54563","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54563","fixed":"4.16.1.","last_modified":"2026-07-15T15:34:04.861Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-w5fv-7x5q-g8qp","primary_source":"","published":"2026-07-15T14:38:54.129Z"},{"affected":"< 4.16.1","affected_versions_present":true,"cve_id":"CVE-2026-54562","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54562","fixed":"4.16.1.","last_modified":"2026-07-15T15:00:16.053Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-x756-g4x3-c64m","primary_source":"","published":"2026-07-15T14:37:37.176Z"},{"affected":"< 4.13.0","affected_versions_present":true,"cve_id":"CVE-2026-25726","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25726","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-04T03:21:18.970Z","patch_url":"https://github.com/cloudreve/cloudreve/security/advisories/GHSA-f8xp-wvcx-p6f4","primary_source":"","published":"2026-04-03T20:06:21.629Z"},{"affected":"3.0.0-beta < unspecified; unspecified \u2264 3.5.3","affected_versions_present":true,"cve_id":"CVE-2022-32167","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-32167","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-29T13:50:36.589Z","patch_url":"","primary_source":"","published":"2022-09-20T14:45:19.000Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"Cloudreve"}}
