{"api_version":"v1","generated_at":"2026-10-07T04:10:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-hapijs-content-87efcdd53509","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/content","name":"content","next_cursor":null,"observations":[{"affected":"< 6.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44974","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44974","fixed":"6.0.2.","last_modified":"2026-07-21T02:16:04.352Z","patch_url":"https://github.com/hapijs/content/security/advisories/GHSA-36hh-x5p5-jgc8","primary_source":"","published":"2026-07-17T20:11:44.250Z"},{"affected":"< 6.0.1","affected_versions_present":true,"cve_id":"CVE-2026-35213","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35213","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-23T15:51:14.160Z","patch_url":"https://github.com/hapijs/content/pull/38","primary_source":"","published":"2026-04-06T20:08:54.811Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"hapijs"}}
