{"api_version":"v1","generated_at":"2026-10-04T16:30:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-elixir-plug-plug-81a14e90eeab","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/plug","name":"plug","next_cursor":null,"observations":[{"affected":"plug: 0.1.0 < 1.16.6, 1.17.0 < 1.17.4, 1.18.0 < 1.18.5, 1.19.1 < 1.19.5, 1.20.0 < 1.20.3, f26876aa67aaeb38e616638aa3efbcc2fe2906a5 < *","affected_versions_present":true,"cve_id":"CVE-2026-56813","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56813","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T21:30:13.749Z","patch_url":"","primary_source":"","published":"2026-07-10T12:51:08.758Z"},{"affected":"plug: 1.4.0-rc.0 < 1.16.6, 1.17.0 < 1.17.4, 1.18.0 < 1.18.5, 1.19.1 < 1.19.5, 1.20.0 < 1.20.3, c52b2f32c90bccd718202bafccb5f95594e30183 < *","affected_versions_present":true,"cve_id":"CVE-2026-56814","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56814","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T21:31:15.419Z","patch_url":"","primary_source":"","published":"2026-07-10T11:14:35.574Z"},{"affected":"1.15.0 < 1.15.5; 1.16.0 < 1.16.4; 1.17.0 < 1.17.2; 1.18.0 < 1.18.3; 1.19.0 < 1.19.3; 712b875d3442c765d8d37e546ffd5ad9f8afcc55 < *","affected_versions_present":true,"cve_id":"CVE-2026-54892","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54892","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T18:21:14.232Z","patch_url":"","primary_source":"","published":"2026-06-23T12:31:12.629Z"},{"affected":"1.4.0 < 1.15.4; 1.16.0 < 1.16.3; 1.17.0 < 1.17.1; 1.18.0 < 1.18.2; 1.19.0 < 1.19.2; c52b2f32c90bccd718202bafccb5f95594e30183 < *","affected_versions_present":true,"cve_id":"CVE-2026-8468","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-8468","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T15:41:29.241Z","patch_url":"","primary_source":"","published":"2026-05-14T10:29:51.062Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"elixir-plug"}}
