{"api_version":"v1","generated_at":"2026-10-07T16:05:00+00:00","product":{"cve_count":9,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-indico-indico-e3eb97b9a6b7","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"indico","next_cursor":null,"observations":[{"affected":"< 3.3.12","affected_versions_present":true,"cve_id":"CVE-2026-33046","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33046","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-24T13:42:19.688Z","patch_url":"https://github.com/indico/indico/security/advisories/GHSA-rm2q-f7jv-3cfp","primary_source":"","published":"2026-03-23T22:45:29.067Z"},{"affected":"< 3.3.11","affected_versions_present":true,"cve_id":"CVE-2026-28352","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28352","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-03T20:29:18.718Z","patch_url":"https://github.com/indico/indico/security/advisories/GHSA-rfpp-2hgm-gp5v","primary_source":"","published":"2026-02-27T21:01:45.740Z"},{"affected":"< 3.3.10","affected_versions_present":true,"cve_id":"CVE-2026-25739","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25739","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-19T19:49:22.187Z","patch_url":"https://github.com/indico/indico/security/advisories/GHSA-jxc4-54g3-j7vp","primary_source":"","published":"2026-02-19T15:39:32.554Z"},{"affected":"< 3.3.10","affected_versions_present":true,"cve_id":"CVE-2026-25738","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25738","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-19T17:34:39.413Z","patch_url":"https://github.com/indico/indico/commit/70d341826116fac5868719a6133f2c26d9345137","primary_source":"","published":"2026-02-19T15:30:54.824Z"},{"affected":"< 3.3.8","affected_versions_present":true,"cve_id":"CVE-2025-59035","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59035","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-11T14:42:48.282Z","patch_url":"https://github.com/indico/indico/security/advisories/GHSA-7cf7-9wrr-vrf4","primary_source":"","published":"2025-09-10T16:03:36.573Z"},{"affected":"< 3.3.8","affected_versions_present":true,"cve_id":"CVE-2025-59034","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59034","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-11T14:42:53.468Z","patch_url":"https://github.com/indico/indico/security/advisories/GHSA-4269-mcfh-cp7q","primary_source":"","published":"2025-09-10T16:01:09.960Z"},{"affected":">= 2.2, < 3.3.7","affected_versions_present":true,"cve_id":"CVE-2025-53640","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53640","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-22T15:29:26.173Z","patch_url":"https://www.vicarius.io/vsociety/posts/cve202553640-mitigate-indico-vulnerability","primary_source":"","published":"2025-07-14T20:14:27.041Z"},{"affected":"< 3.3.4","affected_versions_present":true,"cve_id":"CVE-2024-45399","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45399","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-04T20:17:38.298Z","patch_url":"https://github.com/indico/flask-multipass/commit/0bdcf656d469e5f675cb56fd644d82fea3a97c2a","primary_source":"","published":"2024-09-04T20:12:20.457Z"},{"affected":"< 3.2.6","affected_versions_present":true,"cve_id":"CVE-2023-37901","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-37901","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-10-10T18:58:39.624Z","patch_url":"https://github.com/indico/indico/commit/2ee636d318653fb1ab193803dafbfe3e371d4130","primary_source":"","published":"2023-07-21T18:14:25.481Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"indico"}}
