{"api_version":"v1","generated_at":"2026-10-09T07:15:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-hashicorp-boundary-88488105473c","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/boundary","name":"Boundary","next_cursor":null,"observations":[{"affected":"0.9.0 < 0.21.3","affected_versions_present":true,"cve_id":"CVE-2026-7776","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7776","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-05T14:14:05.799Z","patch_url":"","primary_source":"","published":"2026-05-04T21:34:10.975Z"},{"affected":"0.8.0 < 0.18.2","affected_versions_present":true,"cve_id":"CVE-2024-12289","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-12289","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-13T19:35:10.676Z","patch_url":"","primary_source":"","published":"2024-12-12T22:42:01.595Z"},{"affected":"0.8.0 < 0.15.0","affected_versions_present":true,"cve_id":"CVE-2024-1052","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-1052","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-01T18:26:30.420Z","patch_url":"","primary_source":"","published":"2024-02-05T20:43:53.939Z"},{"affected":"0.10.0 \u2264 0.11.2","affected_versions_present":true,"cve_id":"CVE-2023-0690","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-0690","fixed":"0.12.0.","last_modified":"2025-03-24T20:50:18.849Z","patch_url":"https://discuss.hashicorp.com/t/hcsec-2023-03-boundary-workers-store-rotated-credentials-in-plaintext-even-when-key-management-service-configured/49907","primary_source":"","published":"2023-02-08T18:27:33.548Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"HashiCorp"}}
