{"api_version":"v1","generated_at":"2026-10-07T12:45:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hexpm-hexpm-4a0fa9184b92","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"hexpm","next_cursor":null,"observations":[{"affected":"hexpm: 2025-10-10 < 2026-09-22, 650faa03af511e74c1b3b49ec12d35666b6984c4 < db58cf3a86c7639708ef52ff86de0b4f938e6360","affected_versions_present":true,"cve_id":"CVE-2026-86698","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86698","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-22T18:09:08.676Z","patch_url":"","primary_source":"","published":"2026-09-22T15:51:57.998Z"},{"affected":"2025-10-10 < 2026-08-24; 650faa03af511e74c1b3b49ec12d35666b6984c4 < 50cffd206490c49c92d7b63c8505949682abedb0","affected_versions_present":true,"cve_id":"CVE-2026-75554","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75554","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-25T19:53:55.535Z","patch_url":"","primary_source":"","published":"2026-08-24T20:15:05.791Z"},{"affected":"2025-10-18 < 2026-08-24; 71829cb6f6559bcceb1ef4e43a2fb8cdd3af654b < bf0fb9d208f0acfabf7a2f7467c8231659e322a8","affected_versions_present":true,"cve_id":"CVE-2026-75542","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75542","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-25T19:53:26.196Z","patch_url":"","primary_source":"","published":"2026-08-24T20:14:30.191Z"},{"affected":"hexpm: < 2026-03-10, 82911daf5f8fb2ab44f298e3ba22b90bc1ae3746 < 495f01607d3eae4aed7ad09b2f54f31ec7a7df01","affected_versions_present":true,"cve_id":"CVE-2026-23940","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23940","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-09-08T13:32:42.745Z","patch_url":"https://github.com/hexpm/hexpm/commit/495f01607d3eae4aed7ad09b2f54f31ec7a7df01","primary_source":"","published":"2026-03-13T16:07:53.328Z"},{"affected":"617e44c71f1dd9043870205f371d375c5c4d886d < bb0e42091995945deef10556f58d046a52eb7884; 2025-08-01 < 2026-03-05","affected_versions_present":true,"cve_id":"CVE-2026-21622","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21622","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-21T04:15:20.750Z","patch_url":"https://github.com/hexpm/hexpm/security/advisories/GHSA-6r94-pvwf-mxqm","primary_source":"","published":"2026-03-05T21:18:03.883Z"},{"affected":"71829cb6f6559bcceb1ef4e43a2fb8cdd3af654b < 71c127afebb7ed7cc637eb231b98feb802d62999; 2025-08-18 < 2026-03-05","affected_versions_present":true,"cve_id":"CVE-2026-21621","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21621","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-06T16:44:09.535Z","patch_url":"https://github.com/hexpm/hexpm/commit/71c127afebb7ed7cc637eb231b98feb802d62999","primary_source":"","published":"2026-03-05T19:20:05.831Z"},{"affected":"hexpm: 931ee0ed46fa89218e0400a4f6e6d15f96406050 < 5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0","affected_versions_present":true,"cve_id":"CVE-2026-23939","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23939","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-09-16T15:36:19.353Z","patch_url":"https://github.com/hexpm/hexpm/commit/5d2ccd2f14f45a63225a73fb5b1c937baf36fdc0","primary_source":"","published":"2026-02-26T19:41:18.762Z"},{"affected":"617e44c71f1dd9043870205f371d375c5c4d886d < c692438684ead90c3bcbfb9ccf4e63c768c668a8; 2025-10-01 < 2026-01-19","affected_versions_present":true,"cve_id":"CVE-2026-21618","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21618","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-24T14:16:04.791Z","patch_url":"https://github.com/hexpm/hexpm/commit/c692438684ead90c3bcbfb9ccf4e63c768c668a8","primary_source":"","published":"2026-01-19T14:22:46.770Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"hexpm"}}
