{"api_version":"v1","generated_at":"2026-10-07T21:25:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-go-standard-library-net-http-httputil-cfbbf5f6540c","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"net/http/httputil","next_cursor":null,"observations":[{"affected":"< 1.25.10; 1.26.0-0 < 1.26.3","affected_versions_present":true,"cve_id":"CVE-2026-39825","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39825","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-08T21:30:08.872Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-39825","primary_source":"","published":"2026-05-07T19:41:18.453Z"},{"affected":"< 1.18.7; 1.19.0-0 < 1.19.2","affected_versions_present":true,"cve_id":"CVE-2022-2880","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-2880","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:32:39.111Z","patch_url":"https://go.dev/cl/432976","primary_source":"","published":"2022-10-14T00:00:00.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Go standard library"}}
