{"api_version":"v1","generated_at":"2026-10-08T11:20:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-dragonflydb-dragonfly-4d8e2d6d4af9","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/dragonfly","name":"Dragonfly","next_cursor":null,"observations":[{"affected":"< 1.40.0","affected_versions_present":true,"cve_id":"CVE-2026-62357","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62357","fixed":"1.40.0.","last_modified":"2026-08-19T14:36:42.019Z","patch_url":"https://github.com/dragonflydb/dragonfly/security/advisories/GHSA-cmmv-h748-v93x","primary_source":"","published":"2026-08-18T15:18:52.900Z"},{"affected":"< 1.39.0","affected_versions_present":true,"cve_id":"CVE-2026-54341","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54341","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T18:32:22.364Z","patch_url":"","primary_source":"","published":"2026-06-26T16:42:15.298Z"},{"affected":"< 1.38.9","affected_versions_present":true,"cve_id":"CVE-2026-47206","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47206","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T17:31:48.061Z","patch_url":"","primary_source":"","published":"2026-06-26T16:39:27.710Z"},{"affected":"1.30.1; 1.30.0; 1.28.18","affected_versions_present":true,"cve_id":"CVE-2025-52935","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52935","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-23T12:29:54.589Z","patch_url":"","primary_source":"","published":"2025-06-23T09:27:18.355Z"},{"affected":"\u2264 1.28.2","affected_versions_present":true,"cve_id":"CVE-2025-26269","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-26269","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:08:25.399Z","patch_url":"https://github.com/dragonflydb/dragonfly/issues/4468","primary_source":"","published":"2025-04-17T00:00:00.000Z"},{"affected":"< 1.27.0","affected_versions_present":true,"cve_id":"CVE-2025-26268","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-26268","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-17T19:12:46.786Z","patch_url":"https://github.com/dragonflydb/dragonfly/commit/d1fac0f912edb323a2bdd6404c518cda21eac243","primary_source":"","published":"2025-04-17T00:00:00.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"DragonflyDB"}}
