{"api_version":"v1","generated_at":"2026-10-09T16:10:00+00:00","product":{"cve_count":3,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-kubevela-kubevela-8738b84b26f3","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"kubevela","next_cursor":null,"observations":[{"affected":"< 1.9.14; >= 1.10.0-alpha.1, < 1.10.9; >= 1.11.0-alpha.1, < 1.11.0-alpha.4","affected_versions_present":true,"cve_id":"CVE-2026-55108","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55108","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-28T20:21:47.902Z","patch_url":"","primary_source":"","published":"2026-08-28T16:11:58.923Z"},{"affected":">= 1.6.0, < 1.6.1; < 1.5.9","affected_versions_present":true,"cve_id":"CVE-2022-39383","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39383","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:37:02.312Z","patch_url":"https://github.com/kubevela/kubevela/pull/5000","primary_source":"","published":"2022-11-16T00:00:00.000Z"},{"affected":">= 1.4.0, < 1.4.11; >= 1.5.0, < 1.5.3","affected_versions_present":true,"cve_id":"CVE-2022-36089","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36089","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T17:13:19.449Z","patch_url":"https://github.com/kubevela/kubevela/security/advisories/GHSA-cq42-w295-r29q","primary_source":"","published":"2022-09-07T23:00:15.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"kubevela"}}
