{"api_version":"v1","generated_at":"2026-10-08T12:50:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-knplabs-snappy-32e377e312a0","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/snappy","name":"snappy","next_cursor":null,"observations":[{"affected":"< 1.7.0","affected_versions_present":true,"cve_id":"CVE-2026-46683","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46683","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T14:06:14.719Z","patch_url":"","primary_source":"","published":"2026-06-10T19:53:09.020Z"},{"affected":"< 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-46643","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46643","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T16:15:41.695Z","patch_url":"","primary_source":"","published":"2026-06-10T19:52:59.944Z"},{"affected":"< 1.4.3","affected_versions_present":true,"cve_id":"CVE-2023-41330","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-41330","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-30T15:54:18.428Z","patch_url":"https://github.com/KnpLabs/snappy/commit/d3b742d61a68bf93866032c2c0a7f1486128b67e","primary_source":"","published":"2023-09-06T17:33:21.098Z"},{"affected":"< 1.4.2","affected_versions_present":true,"cve_id":"CVE-2023-28115","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28115","fixed":"1.4.2.","last_modified":"2025-02-25T14:53:10.142Z","patch_url":"https://github.com/KnpLabs/snappy/pull/469","primary_source":"","published":"2023-03-17T21:15:25.113Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"KnpLabs"}}
