{"api_version":"v1","generated_at":"2026-10-08T20:05:00+00:00","product":{"cve_count":10,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-h3js-h3-3b2f9097e6e3","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/h3","name":"h3","next_cursor":null,"observations":[{"affected":"< 1.15.6; 2.0.0-beta.0 < 2.0.1-rc.15","affected_versions_present":true,"cve_id":"CVE-2026-86253","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86253","fixed":"1.15.6; 2.0.1-rc.15","last_modified":"2026-09-10T15:04:40.108Z","patch_url":"https://github.com/h3js/h3/security/advisories/GHSA-wr4h-v87w-p3r7","primary_source":"","published":"2026-09-06T12:00:28.232Z"},{"affected":"< 1.15.9; 2.0.0-beta.0 < 2.0.1-rc.17","affected_versions_present":true,"cve_id":"CVE-2026-86252","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86252","fixed":"1.15.9; 2.0.1-rc.17","last_modified":"2026-09-08T15:13:40.142Z","patch_url":"https://github.com/h3js/h3/security/advisories/GHSA-4hxc-9384-m385","primary_source":"","published":"2026-09-06T12:00:27.561Z"},{"affected":"< 1.15.9","affected_versions_present":true,"cve_id":"CVE-2026-86251","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86251","fixed":"1.15.9","last_modified":"2026-09-09T13:57:41.603Z","patch_url":"https://github.com/h3js/h3/security/advisories/GHSA-72gr-qfp7-vwhw","primary_source":"","published":"2026-09-06T12:00:26.881Z"},{"affected":"h3: 2.0.0-beta.4 < 2.0.1-rc.18","affected_versions_present":true,"cve_id":"CVE-2026-86250","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86250","fixed":"h3: 2.0.1-rc.18","last_modified":"2026-09-18T17:23:10.520Z","patch_url":"https://github.com/h3js/h3/security/advisories/GHSA-q5pr-72pq-83v3","primary_source":"","published":"2026-09-06T12:00:26.211Z"},{"affected":"2.0.1-rc.17 < 2.0.1-rc.18","affected_versions_present":true,"cve_id":"CVE-2026-86205","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86205","fixed":"2.0.1-rc.18","last_modified":"2026-09-08T13:28:55.791Z","patch_url":"https://github.com/h3js/h3/security/advisories/GHSA-fp4x-ggrf-wmc6","primary_source":"","published":"2026-09-06T12:00:25.530Z"},{"affected":">= 2.0.1-alpha.0, < 2.0.1-rc.17","affected_versions_present":true,"cve_id":"CVE-2026-33490","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33490","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-26T18:23:39.653Z","patch_url":"https://github.com/h3js/h3/security/advisories/GHSA-2j6q-whv2-gh6w","primary_source":"","published":"2026-03-26T17:19:15.956Z"},{"affected":">= 2.0.0-0, < 2.0.1-rc.15","affected_versions_present":true,"cve_id":"CVE-2026-33131","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33131","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-20T11:25:53.880Z","patch_url":"","primary_source":"","published":"2026-03-20T10:16:29.556Z"},{"affected":">= 2.0.1-beta.0, < 2.0.1-rc.9","affected_versions_present":true,"cve_id":"CVE-2026-33129","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33129","fixed":"2.0.1-rc.9.","last_modified":"2026-03-20T19:33:49.871Z","patch_url":"https://github.com/h3js/h3/releases/tag/v2.0.1-rc.9","primary_source":"","published":"2026-03-20T09:41:21.933Z"},{"affected":">= 2.0.0, < 2.0.1-rc.15; < 1.15.6","affected_versions_present":true,"cve_id":"CVE-2026-33128","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33128","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-20T11:40:27.956Z","patch_url":"https://github.com/h3js/h3/commit/7791538e15ca22437307c06b78fa155bb73632a6","primary_source":"","published":"2026-03-20T09:37:07.206Z"},{"affected":"< 1.15.5","affected_versions_present":true,"cve_id":"CVE-2026-23527","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23527","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-13T16:48:19.873Z","patch_url":"https://github.com/h3js/h3/commit/618ccf4f37b8b6148bea7f36040471af45bfb097","primary_source":"","published":"2026-01-15T19:24:20.514Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"h3js"}}
