{"api_version":"v1","generated_at":"2026-10-07T01:25:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-coreruleset-coreruleset-892d659a7a77","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"coreruleset","next_cursor":null,"observations":[{"affected":"< 3.3.9; >= 4.0.0-rc1, < 4.25.0","affected_versions_present":true,"cve_id":"CVE-2026-33691","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33691","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-18T19:16:54.006Z","patch_url":"https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w","primary_source":"","published":"2026-04-02T15:03:52.126Z"},{"affected":"< 4.22.0; < 3.3.8","affected_versions_present":true,"cve_id":"CVE-2026-21876","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21876","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-09T15:41:17.073Z","patch_url":"https://github.com/coreruleset/coreruleset/commit/80d80473abf71bd49bf6d3c1ab221e3c74e4eb83","primary_source":"","published":"2026-01-08T13:55:37.102Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"coreruleset"}}
