{"api_version":"v1","generated_at":"2026-10-09T10:55:00+00:00","product":{"cve_count":22,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-cvat-ai-cvat-eb939546e22c","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/nuget/cvat","name":"cvat","next_cursor":null,"observations":[{"affected":"cvat: >= 2.68.0, < 2.70.0","affected_versions_present":true,"cve_id":"CVE-2026-73220","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73220","fixed":"2.70.0.","last_modified":"2026-08-20T16:56:18.566Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-chxx-45vm-qhc9","primary_source":"","published":"2026-08-20T14:32:52.680Z"},{"affected":">= 2.17.0, < 2.72.0","affected_versions_present":true,"cve_id":"CVE-2026-73221","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73221","fixed":"2.72.0.","last_modified":"2026-08-11T20:04:53.774Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-m7p7-6w4m-886p","primary_source":"","published":"2026-08-11T18:22:10.737Z"},{"affected":">= 2.17.0, < 2.72.0","affected_versions_present":true,"cve_id":"CVE-2026-73219","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73219","fixed":"2.72.0.","last_modified":"2026-08-12T22:13:25.986Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-7xhx-3q27-xvcx","primary_source":"","published":"2026-08-11T17:50:29.576Z"},{"affected":">= 2.5.0, < 2.67.0","affected_versions_present":true,"cve_id":"CVE-2026-65986","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65986","fixed":"2.67.0.","last_modified":"2026-08-05T18:54:56.120Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-w6mx-95ff-72cv","primary_source":"","published":"2026-08-04T20:13:47.803Z"},{"affected":">= 1.6.0< 2.65.0","affected_versions_present":true,"cve_id":"CVE-2026-47682","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47682","fixed":"2.65.0.","last_modified":"2026-08-05T14:04:05.549Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-6f87-4g86-p9gw","primary_source":"","published":"2026-08-04T20:00:49.754Z"},{"affected":"< 2.69.0","affected_versions_present":true,"cve_id":"CVE-2026-58373","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58373","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T21:35:03.183Z","patch_url":"https://github.com/cvat-ai/cvat/pull/10807","primary_source":"","published":"2026-06-30T15:58:22.129Z"},{"affected":">= 2.5.0, < 2.64.0","affected_versions_present":true,"cve_id":"CVE-2026-44369","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44369","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-15T18:13:25.009Z","patch_url":"","primary_source":"","published":"2026-05-13T21:32:15.833Z"},{"affected":">= 1.0.0, < 2.55.0","affected_versions_present":true,"cve_id":"CVE-2026-23526","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23526","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T14:44:33.583Z","patch_url":"https://github.com/cvat-ai/cvat/commit/88ac7aa4d5b52271a30f1aa387c0f5745f8f77d4","primary_source":"","published":"2026-01-21T21:40:25.214Z"},{"affected":">= 2.2.0, < 2.55.0","affected_versions_present":true,"cve_id":"CVE-2026-23516","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23516","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T14:44:33.999Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-3m7p-wx65-c7mp","primary_source":"","published":"2026-01-21T21:38:32.971Z"},{"affected":">= 2.8.1, < 2.53.0","affected_versions_present":true,"cve_id":"CVE-2025-68430","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68430","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-19T17:59:36.869Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-3g7v-xjh7-xmqx","primary_source":"","published":"2025-12-19T17:11:46.949Z"},{"affected":"<= 2.4.0, < 2.49.0","affected_versions_present":true,"cve_id":"CVE-2025-64485","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64485","fixed":"2.49.0.","last_modified":"2025-11-10T16:47:40.892Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-x396-w86c-gf6w","primary_source":"","published":"2025-11-07T23:21:06.984Z"},{"affected":">= 1.1.0, < 2.42.0","affected_versions_present":true,"cve_id":"CVE-2025-54573","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54573","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-30T14:45:10.490Z","patch_url":"https://github.com/cvat-ai/cvat/commit/bc20eff16b8406fbb755f6540e6f269da0c9c5b2","primary_source":"","published":"2025-07-30T14:32:03.675Z"},{"affected":">= 2.2.0, < 2.40.0","affected_versions_present":true,"cve_id":"CVE-2025-49135","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49135","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-25T20:04:39.361Z","patch_url":"https://github.com/cvat-ai/cvat/commit/dbafd9c0287489bea00e1db626f64b107f90bfc9","primary_source":"","published":"2025-06-25T15:05:41.938Z"},{"affected":">= 2.4.0, < 2.38.0","affected_versions_present":true,"cve_id":"CVE-2025-48381","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48381","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-30T12:43:13.681Z","patch_url":"https://github.com/cvat-ai/cvat/commit/7136c99fb2c3a5cb2d8c3ca54b4201b9fa6aab5a","primary_source":"","published":"2025-05-30T03:38:24.317Z"},{"affected":">= 1.1.0, < 2.26.0","affected_versions_present":true,"cve_id":"CVE-2025-23045","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-23045","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-01-28T16:16:54.414Z","patch_url":"https://github.com/cvat-ai/cvat/commit/563e1dfde64b15fa042b23f9d09cd854b35f0366","primary_source":"","published":"2025-01-28T15:19:26.196Z"},{"affected":">= 2.0.0, < 2.19.1","affected_versions_present":true,"cve_id":"CVE-2024-47172","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-47172","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-30T15:45:56.182Z","patch_url":"https://github.com/cvat-ai/cvat/commit/59ce6ca784a0d426b2cfb8cf2850ba1d520c03f5","primary_source":"","published":"2024-09-30T15:00:53.528Z"},{"affected":">= 2.16.0, < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2024-47064","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-47064","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-30T16:26:35.340Z","patch_url":"https://github.com/cvat-ai/cvat/commit/0bf45fd5de08a652dffbfb517318a64c2fdbc5cf","primary_source":"","published":"2024-09-30T14:57:12.805Z"},{"affected":">= 2.4.7, < 2.19.0","affected_versions_present":true,"cve_id":"CVE-2024-47063","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-47063","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-30T16:39:39.911Z","patch_url":"https://github.com/cvat-ai/cvat/commit/75c3d573bc9468b718f53b442c2ef69ad1d5de12","primary_source":"","published":"2024-09-30T14:45:02.035Z"},{"affected":">= 2.3.0, < 2.18.0","affected_versions_present":true,"cve_id":"CVE-2024-45393","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45393","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-10T19:25:11.113Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-p3c9-m7jr-jxxj","primary_source":"","published":"2024-09-10T15:04:13.556Z"},{"affected":">= 2.2.0, < 2.14.3","affected_versions_present":true,"cve_id":"CVE-2024-37306","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37306","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T03:50:55.964Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-jpf9-646h-4px7","primary_source":"","published":"2024-06-13T14:18:28.853Z"},{"affected":">= 2.1.0, < 2.14.3","affected_versions_present":true,"cve_id":"CVE-2024-37164","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37164","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T03:50:54.673Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-q684-4jjh-83g6","primary_source":"","published":"2024-06-13T14:10:16.920Z"},{"affected":"< 2.0.0","affected_versions_present":true,"cve_id":"CVE-2022-31188","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31188","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-22T17:48:10.288Z","patch_url":"https://github.com/cvat-ai/cvat/security/advisories/GHSA-7vpj-j5xv-29pr","primary_source":"","published":"2022-08-01T00:00:00.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"cvat-ai"}}
