{"api_version":"v1","generated_at":"2026-10-08T04:50:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-hashgraph-guardian-ae3b5203cbd8","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/guardian","name":"guardian","next_cursor":null,"observations":[{"affected":"\u2264 3.6.0","affected_versions_present":true,"cve_id":"CVE-2026-22674","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22674","fixed":"ba8c566807848cf84360716438056d8d8d2c8362","last_modified":"2026-07-14T15:53:26.682Z","patch_url":"https://github.com/hashgraph/guardian/pull/6190","primary_source":"","published":"2026-06-18T21:08:05.431Z"},{"affected":"\u2264 3.5.1","affected_versions_present":true,"cve_id":"CVE-2026-45248","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45248","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T21:32:55.736Z","patch_url":"https://github.com/hashgraph/guardian/pull/6076","primary_source":"","published":"2026-05-14T21:36:22.995Z"},{"affected":"\u2264 3.5.1","affected_versions_present":true,"cve_id":"CVE-2026-39911","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39911","fixed":"45fbe2f7e0e8feee30105d42d66ed63fb6177ebe","last_modified":"2026-07-14T20:00:18.220Z","patch_url":"https://github.com/hashgraph/guardian/pull/5929","primary_source":"","published":"2026-04-09T17:57:20.440Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"hashgraph"}}
