{"api_version":"v1","generated_at":"2026-10-07T13:35:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-containers-bubblewrap-c22721b13431","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/bubblewrap","name":"bubblewrap","next_cursor":null,"observations":[{"affected":"bubblewrap: >= 0.11.0, < 0.11.2","affected_versions_present":true,"cve_id":"CVE-2026-41163","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41163","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/","last_modified":"2026-09-01T12:04:48.072Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-41163","primary_source":"","published":"2026-05-09T03:56:51.833Z"},{"affected":"< 0.4.1","affected_versions_present":true,"cve_id":"CVE-2020-5291","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-5291","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T08:22:09.099Z","patch_url":"https://github.com/containers/bubblewrap/commit/1f7e2ad948c051054b683461885a0215f1806240","primary_source":"","published":"2020-03-31T18:00:18.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"containers"}}
