{"api_version":"v1","generated_at":"2026-10-07T14:55:00+00:00","product":{"cve_count":10,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-digitalbazaar-forge-25ffaea12ccf","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/forge","name":"forge","next_cursor":null,"observations":[{"affected":"forge: \u2264 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-85393","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-85393","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.5#Upgrading","last_modified":"2026-09-03T19:14:06.547Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-85393","primary_source":"","published":"2026-09-03T18:54:25.878Z"},{"affected":"forge: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-33896","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33896","fixed":"RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-04T12:04:50.960Z","patch_url":"https://github.com/digitalbazaar/forge/commit/2e492832fb25227e6b647cbe1ac981c123171e90","primary_source":"","published":"2026-03-27T20:50:03.418Z"},{"affected":"forge: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-33895","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33895","fixed":"RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-04T12:04:49.718Z","patch_url":"https://github.com/digitalbazaar/forge/commit/bdecf11571c9f1a487cc0fe72fe78ff6dfa96b85","primary_source":"","published":"2026-03-27T20:47:54.492Z"},{"affected":"forge: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-33894","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33894","fixed":"RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-10T12:04:55.128Z","patch_url":"https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp","primary_source":"","published":"2026-03-27T20:45:49.583Z"},{"affected":"forge: < 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-33891","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33891","fixed":"RHSA-2026:24761: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9","last_modified":"2026-09-04T12:04:56.282Z","patch_url":"https://github.com/digitalbazaar/forge/commit/9bb8d67b99d17e4ebb5fd7596cd699e11f25d023","primary_source":"","published":"2026-03-27T20:43:37.725Z"},{"affected":"< 1.3.2","affected_versions_present":true,"cve_id":"CVE-2025-66030","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66030","fixed":"Update to V4.0.800 or later version","last_modified":"2025-11-28T18:25:02.440Z","patch_url":"https://cert-portal.siemens.com/productcert/html/ssa-485750.html","primary_source":"","published":"2025-11-26T22:23:41.548Z"},{"affected":"< 1.3.2","affected_versions_present":true,"cve_id":"CVE-2025-66031","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66031","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/migration_toolkit_for_virtualization/2.9/html-single/migrating_your_virtual_machines_to_red_hat_openshift_virtualization/index#assembly_upgrading-uninstalling-mtv_mtv","last_modified":"2025-11-28T18:27:06.242Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-66031","primary_source":"","published":"2025-11-26T22:23:26.013Z"},{"affected":"< 1.3.0","affected_versions_present":true,"cve_id":"CVE-2022-24772","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24772","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:46:10.614Z","patch_url":"https://github.com/digitalbazaar/forge/commit/3f0b49a0573ef1bb7af7f5673c0cfebf00424df1","primary_source":"","published":"2022-03-18T13:30:20.000Z"},{"affected":"< 1.3.0","affected_versions_present":true,"cve_id":"CVE-2022-24773","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24773","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:46:17.431Z","patch_url":"https://github.com/digitalbazaar/forge/commit/3f0b49a0573ef1bb7af7f5673c0cfebf00424df1","primary_source":"","published":"2022-03-18T13:30:14.000Z"},{"affected":"< 1.3.0","affected_versions_present":true,"cve_id":"CVE-2022-24771","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24771","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:46:25.686Z","patch_url":"https://github.com/digitalbazaar/forge/commit/3f0b49a0573ef1bb7af7f5673c0cfebf00424df1","primary_source":"","published":"2022-03-18T13:25:11.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"digitalbazaar"}}
