{"api_version":"v1","generated_at":"2026-10-08T12:20:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-freedomofpress-securedrop-client-b39646eabb0b","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"securedrop-client","next_cursor":null,"observations":[{"affected":"securedrop-client: < 1.3.1","affected_versions_present":true,"cve_id":"CVE-2026-49996","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49996","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-20T19:48:57.931Z","patch_url":"","primary_source":"","published":"2026-08-20T18:55:57.513Z"},{"affected":"< 0.17.5","affected_versions_present":true,"cve_id":"CVE-2026-35465","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35465","fixed":"0.17.5.","last_modified":"2026-04-20T15:47:43.822Z","patch_url":"https://github.com/freedomofpress/securedrop-client/commit/e518adaf897e7838467ccf9e1f28152ae6fe3655","primary_source":"","published":"2026-04-18T00:41:16.594Z"},{"affected":"< 0.14.1; = 1.0.0","affected_versions_present":true,"cve_id":"CVE-2025-24889","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-24889","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T19:08:36.897Z","patch_url":"","primary_source":"","published":"2025-02-13T17:34:36.991Z"},{"affected":"< 0.14.1","affected_versions_present":true,"cve_id":"CVE-2025-24888","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-24888","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T19:09:03.935Z","patch_url":"","primary_source":"","published":"2025-02-13T17:32:38.766Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"freedomofpress"}}
