{"api_version":"v1","generated_at":"2026-10-07T18:40:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-fastify-reply-from-fastify-reply-from-3532eaa92339","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/%40fastify/reply-from","name":"@fastify/reply-from","next_cursor":null,"observations":[{"affected":"8.3.1 < 12.6.4","affected_versions_present":true,"cve_id":"CVE-2026-16158","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16158","fixed":"12.6.4","last_modified":"2026-07-20T15:15:50.016Z","patch_url":"https://github.com/fastify/fastify-reply-from/security/advisories/GHSA-v574-6498-x57v","primary_source":"","published":"2026-07-18T12:28:17.262Z"},{"affected":"< 12.6.2; < 11.4.4","affected_versions_present":true,"cve_id":"CVE-2026-33805","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33805","fixed":"12.6.2; 11.4.4","last_modified":"2026-07-15T01:06:04.635Z","patch_url":"https://cna.openjsf.org/security-advisories.html","primary_source":"","published":"2026-04-15T10:13:25.147Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"@fastify/reply-from"}}
