{"api_version":"v1","generated_at":"2026-10-09T12:15:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-corazawaf-coraza-8585f91a0e93","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"coraza","next_cursor":null,"observations":[{"affected":"< 3.3.3","affected_versions_present":true,"cve_id":"CVE-2025-29914","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-29914","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-20T18:18:27.514Z","patch_url":"","primary_source":"","published":"2025-03-20T17:44:59.024Z"},{"affected":"< 3.0.1","affected_versions_present":true,"cve_id":"CVE-2023-40586","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-40586","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-02T14:41:35.285Z","patch_url":"https://github.com/corazawaf/coraza/commit/a5239ba3ce839e14d9b4f9486e1b4a403dcade8c","primary_source":"","published":"2023-08-25T20:35:27.459Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"corazawaf"}}
