{"api_version":"v1","generated_at":"2026-10-08T02:00:00+00:00","product":{"cve_count":6,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-jsonata-js-jsonata-6b517d3a6136","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/jsonata","name":"jsonata","next_cursor":null,"observations":[{"affected":"< 1.8.8; >= 2.0.0, < 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-77415","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77415","fixed":"For more about Red Hat Developer Hub, see References links","last_modified":"2026-08-25T16:55:27.467Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-77415","primary_source":"","published":"2026-08-21T21:01:09.203Z"},{"affected":"< 1.8.8; >= 2.0.0, < 2.2.1","affected_versions_present":true,"cve_id":"CVE-2026-77414","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77414","fixed":"For more about Red Hat Developer Hub, see References links","last_modified":"2026-08-26T17:42:09.319Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-77414","primary_source":"","published":"2026-08-21T20:51:43.500Z"},{"affected":"< 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-77413","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77413","fixed":"For more about Red Hat Developer Hub, see References links","last_modified":"2026-08-24T19:42:37.844Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-77413","primary_source":"","published":"2026-08-21T20:47:08.457Z"},{"affected":">= 2.0.0, < 2.2.0; < 1.8.9","affected_versions_present":true,"cve_id":"CVE-2026-52746","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-52746","fixed":"2.2.0","last_modified":"2026-08-03T20:50:28.984Z","patch_url":"https://github.com/jsonata-js/jsonata/security/advisories/GHSA-86vw-mfpg-wwv9","primary_source":"","published":"2026-07-17T18:32:47.173Z"},{"affected":"2.0; 2.1; 2.2.0","affected_versions_present":true,"cve_id":"CVE-2026-12208","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-12208","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-15T19:25:11.446Z","patch_url":"","primary_source":"","published":"2026-06-15T02:00:08.916Z"},{"affected":">= 1.4.0, < 1.8.7; >= 2.0.0, < 2.0.4","affected_versions_present":true,"cve_id":"CVE-2024-27307","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27307","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-13T17:23:40.132Z","patch_url":"https://github.com/jsonata-js/jsonata/commit/1d579dbe99c19fbe509f5ba2c6db7959b0d456d1","primary_source":"","published":"2024-03-06T19:24:16.876Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"jsonata-js"}}
