{"api_version":"v1","generated_at":"2026-10-08T13:45:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-kepano-defuddle-6dc62b17b06b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/defuddle","name":"defuddle","next_cursor":null,"observations":[{"affected":"defuddle: < 0.19.1","affected_versions_present":true,"cve_id":"CVE-2026-61824","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61824","fixed":"0.19.1.","last_modified":"2026-08-24T19:48:53.974Z","patch_url":"https://github.com/kepano/defuddle/security/advisories/GHSA-jg4p-g6xj-4qmf","primary_source":"","published":"2026-08-21T20:12:53.225Z"},{"affected":"< 0.9.0","affected_versions_present":true,"cve_id":"CVE-2026-30830","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30830","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-10T17:58:06.614Z","patch_url":"https://github.com/kepano/defuddle/commit/f154cb740ee603431b69638273af737a27156df9","primary_source":"","published":"2026-03-07T05:49:15.964Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"kepano"}}
