{"api_version":"v1","generated_at":"2026-10-10T08:15:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-kumahq-kuma-eea98467de12","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/kuma","name":"kuma","next_cursor":null,"observations":[{"affected":"kuma: < 2.7.26","affected_versions_present":true,"cve_id":"CVE-2026-50166","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50166","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-16T15:50:24.712Z","patch_url":"","primary_source":"","published":"2026-09-15T14:52:30.085Z"},{"affected":"kuma: < 2.7.26, >= 2.8.0, < 2.9.16, >= 2.10.0, < 2.11.14, >= 2.12.0, < 2.12.11, >= 2.13.0, < 2.13.7","affected_versions_present":true,"cve_id":"CVE-2026-52724","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-52724","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-15T15:21:20.402Z","patch_url":"","primary_source":"","published":"2026-09-15T14:50:32.257Z"},{"affected":"< 2.7.25; >= 2.9.0, < 2.9.15; >= 2.11.0, < 2.11.13; >= 2.12.0, < 2.12.10; >= 2.13.0, < 2.13.5","affected_versions_present":true,"cve_id":"CVE-2026-45021","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45021","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-28T19:30:33.327Z","patch_url":"","primary_source":"","published":"2026-05-28T17:45:14.434Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"kumahq"}}
