{"api_version":"v1","generated_at":"2026-10-08T19:40:00+00:00","product":{"cve_count":18,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-harttle-liquidjs-63131406b872","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/liquidjs","name":"liquidjs","next_cursor":null,"observations":[{"affected":"liquidjs: < 10.27.2","affected_versions_present":true,"cve_id":"CVE-2026-106120","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-106120","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T18:04:14.907Z","patch_url":"","primary_source":"","published":"2026-10-06T18:04:14.907Z"},{"affected":"< 10.27.2","affected_versions_present":true,"cve_id":"CVE-2026-69222","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-69222","fixed":"10.27.2.","last_modified":"2026-08-21T21:47:58.206Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-4r6h-5v86-94p3","primary_source":"","published":"2026-08-19T20:51:44.218Z"},{"affected":">= 10.26.0, < 10.27.1","affected_versions_present":true,"cve_id":"CVE-2026-61556","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61556","fixed":"10.27.1.","last_modified":"2026-08-25T14:16:38.259Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-m7fp-h3p4-hr49","primary_source":"","published":"2026-08-19T20:49:56.020Z"},{"affected":"liquidjs: < 10.26.0","affected_versions_present":true,"cve_id":"CVE-2026-45618","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45618","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T14:07:35.168Z","patch_url":"","primary_source":"","published":"2026-08-11T19:27:09.777Z"},{"affected":"< 10.27.1","affected_versions_present":true,"cve_id":"CVE-2026-55575","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55575","fixed":"10.27.1.","last_modified":"2026-07-09T14:00:04.585Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-g357-x5c3-c72p","primary_source":"","published":"2026-07-08T19:32:01.216Z"},{"affected":"< 10.26.0","affected_versions_present":true,"cve_id":"CVE-2026-45357","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45357","fixed":"10.26.0.","last_modified":"2026-06-18T12:49:15.361Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-hh27-hf48-9f5q","primary_source":"","published":"2026-06-17T22:32:20.643Z"},{"affected":"< 10.26.0","affected_versions_present":true,"cve_id":"CVE-2026-44646","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44646","fixed":"10.26.0.","last_modified":"2026-06-18T13:53:51.906Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-9x9p-qf8f-mvjg","primary_source":"","published":"2026-06-17T22:25:15.319Z"},{"affected":"< 10.26.0","affected_versions_present":true,"cve_id":"CVE-2026-45617","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45617","fixed":"10.26.0.","last_modified":"2026-06-18T15:46:28.241Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-r7g9-xpmj-5fcq","primary_source":"","published":"2026-06-17T22:14:38.396Z"},{"affected":"< 10.26.0","affected_versions_present":true,"cve_id":"CVE-2026-44645","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44645","fixed":"10.26.0.","last_modified":"2026-06-18T19:05:32.418Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-8xx9-69p8-7jp3","primary_source":"","published":"2026-06-17T22:08:19.354Z"},{"affected":"< 10.26.0","affected_versions_present":true,"cve_id":"CVE-2026-44644","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44644","fixed":"10.26.0.","last_modified":"2026-06-18T13:09:26.903Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-2qv6-9wx5-cwv4","primary_source":"","published":"2026-06-17T21:50:24.743Z"},{"affected":"< 10.25.7","affected_versions_present":true,"cve_id":"CVE-2026-41311","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41311","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-11T15:04:09.635Z","patch_url":"https://github.com/harttle/liquidjs/commit/e2311dfd6e82f73509308aa8a3a1fafc92e226f0","primary_source":"","published":"2026-05-09T04:03:25.488Z"},{"affected":"< 10.25.3","affected_versions_present":true,"cve_id":"CVE-2026-39859","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39859","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-10T20:45:55.071Z","patch_url":"","primary_source":"","published":"2026-04-08T19:45:21.747Z"},{"affected":"< 10.25.4","affected_versions_present":true,"cve_id":"CVE-2026-39412","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39412","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-09T13:53:27.859Z","patch_url":"https://github.com/harttle/liquidjs/commit/e743da0020d34e2ee547e1cc1a86b58377ebe1ce","primary_source":"","published":"2026-04-08T19:39:17.780Z"},{"affected":"< 10.25.3","affected_versions_present":true,"cve_id":"CVE-2026-35525","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35525","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T19:53:00.573Z","patch_url":"","primary_source":"","published":"2026-04-08T19:30:24.802Z"},{"affected":"< 10.25.3","affected_versions_present":true,"cve_id":"CVE-2026-34166","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34166","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-10T20:37:03.164Z","patch_url":"https://github.com/harttle/liquidjs/commit/abc058be0f33d6372cd2216f4945183167abeb25","primary_source":"","published":"2026-04-08T17:52:05.849Z"},{"affected":"< 10.25.1","affected_versions_present":true,"cve_id":"CVE-2026-33285","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33285","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-28T02:08:05.711Z","patch_url":"https://github.com/harttle/liquidjs/commit/95ddefc056a11a44d9e753fd47a39db2c241e578","primary_source":"","published":"2026-03-26T00:34:25.169Z"},{"affected":"< 10.25.1","affected_versions_present":true,"cve_id":"CVE-2026-33287","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33287","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-26T15:02:26.164Z","patch_url":"https://github.com/harttle/liquidjs/commit/35d523026345d80458df24c72e653db78b5d061d","primary_source":"","published":"2026-03-26T00:33:20.024Z"},{"affected":"< 10.25.0","affected_versions_present":true,"cve_id":"CVE-2026-30952","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30952","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-11T14:39:22.286Z","patch_url":"https://github.com/harttle/liquidjs/security/advisories/GHSA-wmfp-5q7x-987x","primary_source":"","published":"2026-03-10T20:25:20.176Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"harttle"}}
