{"api_version":"v1","generated_at":"2026-10-08T19:55:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-galaxyproject-galaxy-1619d472b916","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/galaxy","name":"galaxy","next_cursor":null,"observations":[{"affected":"< 21.05","affected_versions_present":true,"cve_id":"CVE-2024-42351","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42351","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-20T20:08:03.491Z","patch_url":"https://github.com/galaxyproject/galaxy/security/advisories/GHSA-5639-cmph-9j4v","primary_source":"","published":"2024-09-20T18:56:53.987Z"},{"affected":"< 24.1.1","affected_versions_present":true,"cve_id":"CVE-2024-42346","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42346","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-20T20:09:40.416Z","patch_url":"https://github.com/galaxyproject/galaxy/security/advisories/GHSA-x6w7-3gwf-qr9r","primary_source":"","published":"2024-09-20T18:53:01.373Z"},{"affected":"< 22.05","affected_versions_present":true,"cve_id":"CVE-2023-42812","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-42812","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-24T14:25:37.165Z","patch_url":"","primary_source":"","published":"2023-09-22T16:07:02.731Z"},{"affected":"< 22.01","affected_versions_present":true,"cve_id":"CVE-2023-27578","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-27578","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-25T14:52:07.791Z","patch_url":"https://github.com/galaxyproject/galaxy/security/advisories/GHSA-j8q2-r4g5-f22j","primary_source":"","published":"2023-03-20T19:00:58.106Z"},{"affected":">= 22.01, <= 22.05","affected_versions_present":true,"cve_id":"CVE-2022-23470","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23470","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:32:08.764Z","patch_url":"https://github.com/galaxyproject/galaxy/security/advisories/GHSA-grjf-2ghx-q77x","primary_source":"","published":"2022-12-06T17:37:23.638Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"galaxyproject"}}
