{"api_version":"v1","generated_at":"2026-10-07T12:50:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-hapijs-joi-266bb6db95fd","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/joi","name":"joi","next_cursor":null,"observations":[{"affected":"joi: 17.2.0 < 17.13.7, 18.0.0 < 18.2.6","affected_versions_present":true,"cve_id":"CVE-2026-92599","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92599","fixed":"joi: 17.13.7, 18.2.6","last_modified":"2026-09-18T20:06:43.275Z","patch_url":"https://github.com/hapijs/joi/security/advisories/GHSA-6h2x-m376-mqjq","primary_source":"","published":"2026-09-16T21:47:03.073Z"},{"affected":"joi: 16.0.0 < 17.13.8, 18.0.0 < 18.2.9","affected_versions_present":true,"cve_id":"CVE-2026-90771","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90771","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/","last_modified":"2026-09-24T14:21:52.339Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-90771","primary_source":"","published":"2026-09-13T10:45:42.498Z"},{"affected":">= 16.0.0, <= 17.1.1; >= 17.2.0, < 17.13.6; >= 18.0.0, < 18.2.5","affected_versions_present":true,"cve_id":"CVE-2026-84368","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84368","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-02T12:18:07.627Z","patch_url":"","primary_source":"","published":"2026-09-01T20:36:51.859Z"},{"affected":">= 16.0.0, < 17.13.5; >= 18.0.0, < 18.2.4","affected_versions_present":true,"cve_id":"CVE-2026-84367","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-84367","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-03T15:58:42.656Z","patch_url":"","primary_source":"","published":"2026-09-01T20:33:29.295Z"},{"affected":"< 17.13.4; >= 18.0.0, < 18.2.1","affected_versions_present":true,"cve_id":"CVE-2026-48038","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48038","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T13:27:13.334Z","patch_url":"","primary_source":"","published":"2026-07-14T19:24:32.644Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"hapijs"}}
