{"api_version":"v1","generated_at":"2026-10-09T08:25:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-jellyfin-jellyfin-4e8afc6261e1","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/jellyfin","name":"jellyfin","next_cursor":null,"observations":[{"affected":"< 10.11.9","affected_versions_present":true,"cve_id":"CVE-2026-49220","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49220","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-24T19:19:55.345Z","patch_url":"","primary_source":"","published":"2026-06-24T18:23:04.925Z"},{"affected":"< 10.11.10","affected_versions_present":true,"cve_id":"CVE-2026-48793","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48793","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T03:56:00.432Z","patch_url":"","primary_source":"","published":"2026-06-24T18:22:18.293Z"},{"affected":"< 10.11.10","affected_versions_present":true,"cve_id":"CVE-2026-49246","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49246","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T20:00:30.296Z","patch_url":"","primary_source":"","published":"2026-06-24T18:21:25.846Z"},{"affected":">= 10.9.0, < 10.11.10","affected_versions_present":true,"cve_id":"CVE-2026-49247","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49247","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T03:55:58.837Z","patch_url":"","primary_source":"","published":"2026-06-24T18:18:46.137Z"},{"affected":"< 10.11.7","affected_versions_present":true,"cve_id":"CVE-2026-35034","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35034","fixed":"10.11.7.","last_modified":"2026-04-15T17:48:39.733Z","patch_url":"https://github.com/jellyfin/jellyfin/security/advisories/GHSA-v2jv-54xj-h76w","primary_source":"","published":"2026-04-14T22:31:44.796Z"},{"affected":"< 10.11.7","affected_versions_present":true,"cve_id":"CVE-2026-35033","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35033","fixed":"10.11.7.","last_modified":"2026-04-15T13:36:26.787Z","patch_url":"https://github.com/jellyfin/jellyfin/security/advisories/GHSA-jh22-fw8w-2v9x","primary_source":"","published":"2026-04-14T22:28:47.558Z"},{"affected":"< 10.11.7","affected_versions_present":true,"cve_id":"CVE-2026-35032","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35032","fixed":"10.11.7.","last_modified":"2026-04-15T20:02:29.887Z","patch_url":"https://github.com/jellyfin/jellyfin/security/advisories/GHSA-8fw7-f233-ffr8","primary_source":"","published":"2026-04-14T22:25:35.729Z"},{"affected":"< 10.11.7","affected_versions_present":true,"cve_id":"CVE-2026-35031","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35031","fixed":"10.11.7.","last_modified":"2026-04-16T13:56:06.801Z","patch_url":"https://github.com/jellyfin/jellyfin/security/advisories/GHSA-j2hf-x4q5-47j3","primary_source":"","published":"2026-04-14T22:18:30.565Z"},{"affected":"< 10.10.7","affected_versions_present":true,"cve_id":"CVE-2025-31499","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-31499","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-16T14:43:50.406Z","patch_url":"https://github.com/jellyfin/jellyfin/commit/79f3ce53257c5291887cd52d8ac735b5252c9a97","primary_source":"","published":"2025-04-15T20:36:24.078Z"},{"affected":">= 10.9.0, < 10.10.7","affected_versions_present":true,"cve_id":"CVE-2025-32012","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32012","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-15T20:13:13.413Z","patch_url":"https://github.com/jellyfin/jellyfin/commit/f625665cb116a7e3feb8b79aaf1ed39a956e0585","primary_source":"","published":"2025-04-15T20:08:52.658Z"},{"affected":">= 10.8.0, < 10.9.10","affected_versions_present":true,"cve_id":"CVE-2024-43801","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43801","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-03T19:16:00.791Z","patch_url":"https://github.com/jellyfin/jellyfin/pull/12490","primary_source":"","published":"2024-09-02T16:26:58.884Z"},{"affected":"< 10.8.13","affected_versions_present":true,"cve_id":"CVE-2023-48702","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-48702","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-02T21:37:54.384Z","patch_url":"https://github.com/jellyfin/jellyfin/commit/83d2c69516471e2db72d9273c6a04247d0f37c86","primary_source":"","published":"2023-12-13T20:53:28.786Z"},{"affected":"< 10.8.13","affected_versions_present":true,"cve_id":"CVE-2023-49096","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49096","fixed":"10.8.13.","last_modified":"2025-05-28T15:44:52.025Z","patch_url":"https://github.com/jellyfin/jellyfin/commit/a656799dc879d16d21bf2ce7ad412ebd5d45394a","primary_source":"","published":"2023-12-06T19:14:11.108Z"},{"affected":">= 10.8.0, < 10.8.10","affected_versions_present":true,"cve_id":"CVE-2023-30626","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-30626","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-12T16:34:36.816Z","patch_url":"https://github.com/jellyfin/jellyfin/security/advisories/GHSA-9p5f-5x8v-x65m","primary_source":"","published":"2023-04-24T20:06:39.400Z"},{"affected":"<= 10.7.2","affected_versions_present":true,"cve_id":"CVE-2021-29490","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-29490","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T22:11:05.554Z","patch_url":"https://github.com/jellyfin/jellyfin/security/advisories/GHSA-rgjw-4fwc-9v96","primary_source":"","published":"2021-05-05T18:25:13.000Z"},{"affected":"< 10.7.1","affected_versions_present":true,"cve_id":"CVE-2021-21402","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21402","fixed":"10.7.1.","last_modified":"2024-08-03T18:09:16.077Z","patch_url":"https://github.com/jellyfin/jellyfin/commit/0183ef8e89195f420c48d2600bc0b72f6d3a7fd7","primary_source":"","published":"2021-03-23T19:35:13.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"jellyfin"}}
