{"api_version":"v1","generated_at":"2026-10-09T00:15:00+00:00","product":{"cve_count":6,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-feathersjs-feathers-f2802807181b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/feathers","name":"feathers","next_cursor":null,"observations":[{"affected":"< 5.0.45","affected_versions_present":true,"cve_id":"CVE-2026-54335","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54335","fixed":"5.0.45.","last_modified":"2026-07-20T17:38:02.512Z","patch_url":"https://github.com/feathersjs/feathers/security/advisories/GHSA-28xv-ph75-77wh","primary_source":"","published":"2026-07-17T20:56:51.857Z"},{"affected":">= 5.0.0, < 5.0.42","affected_versions_present":true,"cve_id":"CVE-2026-29792","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29792","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T14:10:22.938Z","patch_url":"","primary_source":"","published":"2026-03-10T20:06:34.801Z"},{"affected":"< 5.0.40","affected_versions_present":true,"cve_id":"CVE-2026-27193","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27193","fixed":"5.0.40.","last_modified":"2026-02-25T21:24:17.388Z","patch_url":"https://github.com/feathersjs/feathers/commit/ee19a0ae9bc2ebf23b1fe598a1f7361981b65401","primary_source":"","published":"2026-02-21T04:09:06.855Z"},{"affected":"< 5.0.40","affected_versions_present":true,"cve_id":"CVE-2026-27192","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27192","fixed":"5.0.40.","last_modified":"2026-02-23T19:13:45.407Z","patch_url":"https://github.com/feathersjs/feathers/commit/ee19a0ae9bc2ebf23b1fe598a1f7361981b65401","primary_source":"","published":"2026-02-21T03:50:35.954Z"},{"affected":"< 5.0.40","affected_versions_present":true,"cve_id":"CVE-2026-27191","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27191","fixed":"5.0.40.","last_modified":"2026-02-25T21:24:54.980Z","patch_url":"https://github.com/feathersjs/feathers/commit/ee19a0ae9bc2ebf23b1fe598a1f7361981b65401","primary_source":"","published":"2026-02-21T03:23:28.340Z"},{"affected":"< 4.5.18; >= 5.0.0, < 5.0.8","affected_versions_present":true,"cve_id":"CVE-2023-37899","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37899","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-28T15:12:04.645Z","patch_url":"https://github.com/feathersjs/feathers/pull/3241","primary_source":"","published":"2023-07-19T19:45:31.386Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"feathersjs"}}
