{"api_version":"v1","generated_at":"2026-10-08T14:05:00+00:00","product":{"cve_count":14,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-dragonflyoss-dragonfly-041e9699f508","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/dragonfly","name":"dragonfly","next_cursor":null,"observations":[{"affected":"dragonfly: < 2.4.4","affected_versions_present":true,"cve_id":"CVE-2026-49254","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49254","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-15T18:03:27.313Z","patch_url":"","primary_source":"","published":"2026-09-15T14:06:21.309Z"},{"affected":"dragonfly: < 2.4.4-rc.3","affected_versions_present":true,"cve_id":"CVE-2026-54637","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54637","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-16T18:11:53.807Z","patch_url":"","primary_source":"","published":"2026-09-15T14:04:50.124Z"},{"affected":"< 2.4.1-rc.1","affected_versions_present":true,"cve_id":"CVE-2026-24124","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24124","fixed":"2.4.1-rc.1.","last_modified":"2026-02-26T14:44:30.933Z","patch_url":"https://github.com/dragonflyoss/dragonfly/commit/9fb9a2dfde3100f32dc7f48eabee4c2b64eac55f","primary_source":"","published":"2026-01-22T22:20:20.820Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59410","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59410","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T15:47:03.096Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-mcvp-rpgg-9273","primary_source":"","published":"2025-09-17T19:58:54.083Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59354","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59354","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T15:51:14.626Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-hx2h-vjw2-8r54","primary_source":"","published":"2025-09-17T19:57:07.374Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59353","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59353","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T17:44:13.154Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-255v-qv84-29p5","primary_source":"","published":"2025-09-17T19:53:36.109Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59352","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59352","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T17:43:17.540Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-79hx-3fp8-hj66","primary_source":"","published":"2025-09-17T19:50:38.914Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59351","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59351","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T17:42:35.283Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-4mhv-8rh3-4ghw","primary_source":"","published":"2025-09-17T19:46:41.322Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59350","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59350","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T17:42:07.237Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-c2fc-9q9c-5486","primary_source":"","published":"2025-09-17T19:43:24.085Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59349","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59349","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-18T17:35:48.904Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-8425-8r2f-mrv6","primary_source":"","published":"2025-09-17T19:41:03.632Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59348","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59348","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-17T19:45:03.134Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-2qgr-gfvj-qpcr","primary_source":"","published":"2025-09-17T19:30:22.841Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59347","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59347","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-17T19:34:06.018Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-98x5-jw98-6c97","primary_source":"","published":"2025-09-17T19:23:20.557Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59346","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59346","fixed":"2.1.0.","last_modified":"2025-09-17T19:31:01.954Z","patch_url":"https://github.com/dragonflyoss/dragonfly/security/advisories/GHSA-g2rq-jv54-wcpr","primary_source":"","published":"2025-09-17T19:20:23.153Z"},{"affected":"< 2.1.0","affected_versions_present":true,"cve_id":"CVE-2025-59345","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59345","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-13T15:22:12.692Z","patch_url":"","primary_source":"","published":"2025-09-17T19:05:53.441Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"dragonflyoss"}}
