{"api_version":"v1","generated_at":"2026-10-08T05:10:00+00:00","product":{"cve_count":12,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-hashicorp-tooling-6034841c4b3b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/tooling","name":"Tooling","next_cursor":null,"observations":[{"affected":"0.27.2 < 0.43.0","affected_versions_present":true,"cve_id":"CVE-2026-87993","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87993","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-10T19:21:18.274Z","patch_url":"","primary_source":"","published":"2026-09-10T19:00:08.728Z"},{"affected":"1.3.0 < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2026-8715","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-8715","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-28T22:07:19.694Z","patch_url":"","primary_source":"","published":"2026-08-13T20:27:39.489Z"},{"affected":"0.1.0 < 0.1.4","affected_versions_present":true,"cve_id":"CVE-2026-16326","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16326","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-29T19:10:11.027Z","patch_url":"","primary_source":"","published":"2026-07-29T18:40:08.796Z"},{"affected":"0.1.0 < 0.1.4","affected_versions_present":true,"cve_id":"CVE-2026-16328","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16328","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-29T19:11:05.959Z","patch_url":"","primary_source":"","published":"2026-07-29T18:32:39.870Z"},{"affected":"0.3.0 < 1.1.0","affected_versions_present":true,"cve_id":"CVE-2026-16498","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16498","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-28T18:39:15.712Z","patch_url":"","primary_source":"","published":"2026-07-28T17:57:45.748Z"},{"affected":"0.3.0 < 1.1.0","affected_versions_present":true,"cve_id":"CVE-2026-16496","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16496","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-28T18:43:58.385Z","patch_url":"","primary_source":"","published":"2026-07-28T17:57:36.795Z"},{"affected":"0.3.0 < 1.1.0","affected_versions_present":true,"cve_id":"CVE-2026-14869","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14869","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-28T19:19:31.237Z","patch_url":"","primary_source":"","published":"2026-07-28T17:53:58.707Z"},{"affected":"0.1.0 < 0.42.1","affected_versions_present":true,"cve_id":"CVE-2026-14361","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14361","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-08T20:37:56.570Z","patch_url":"","primary_source":"","published":"2026-07-08T20:11:32.799Z"},{"affected":"0.1.0 < 0.42.0","affected_versions_present":true,"cve_id":"CVE-2026-5061","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5061","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-12T15:43:01.985Z","patch_url":"","primary_source":"","published":"2026-05-12T13:58:20.409Z"},{"affected":"< 1.8.6","affected_versions_present":true,"cve_id":"CVE-2026-4660","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-4660","fixed":"Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index","last_modified":"2026-07-15T00:50:08.124Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-4660","primary_source":"","published":"2026-04-09T13:47:46.953Z"},{"affected":"4.2.0 < 5.5.0","affected_versions_present":true,"cve_id":"CVE-2025-13357","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-13357","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-17T17:57:56.094Z","patch_url":"","primary_source":"","published":"2025-11-21T15:02:27.081Z"},{"affected":"< 0.5.0","affected_versions_present":true,"cve_id":"CVE-2025-1293","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-1293","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-20T14:24:57.660Z","patch_url":"","primary_source":"","published":"2025-02-20T00:28:37.246Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"HashiCorp"}}
