{"api_version":"v1","generated_at":"2026-10-08T19:00:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-langchain-ai-langgraph-a21016a9ba1b","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"langgraph","next_cursor":null,"observations":[{"affected":"langgraph: >= 0.1.45, < 0.4.4","affected_versions_present":true,"cve_id":"CVE-2026-104873","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-104873","fixed":"0.4.4.","last_modified":"2026-10-05T15:32:10.019Z","patch_url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-fvww-7h3r-vfhp","primary_source":"","published":"2026-10-02T20:06:07.090Z"},{"affected":"< 3.1.1","affected_versions_present":true,"cve_id":"CVE-2026-71433","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-71433","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-07T14:51:28.324Z","patch_url":"","primary_source":"","published":"2026-08-06T19:03:09.362Z"},{"affected":"1.2.0; 1.2.1; 1.2.2; 1.2.3; 1.2.4","affected_versions_present":true,"cve_id":"CVE-2026-14742","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14742","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-06T17:59:43.776Z","patch_url":"","primary_source":"","published":"2026-07-05T10:45:09.243Z"},{"affected":"< 1.2.2; < 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-48775","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48775","fixed":"4.1.1.","last_modified":"2026-06-16T18:42:07.221Z","patch_url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-fjqc-hq36-qh5p","primary_source":"","published":"2026-06-16T17:53:10.808Z"},{"affected":"<= 1.0.9","affected_versions_present":true,"cve_id":"CVE-2026-28277","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28277","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-06T18:04:29.687Z","patch_url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-g48c-2wqr-h844","primary_source":"","published":"2026-03-05T19:10:36.865Z"},{"affected":"< 3.0.1","affected_versions_present":true,"cve_id":"CVE-2025-67644","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-67644","fixed":"3.0.1.","last_modified":"2025-12-11T15:35:59.816Z","patch_url":"https://github.com/langchain-ai/langgraph/commit/297242913f8ad2143ee3e2f72e67db0911d48e2a","primary_source":"","published":"2025-12-10T23:37:36.182Z"},{"affected":"< 3.0.0","affected_versions_present":true,"cve_id":"CVE-2025-64439","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64439","fixed":"3.0.0.","last_modified":"2025-11-07T20:21:52.610Z","patch_url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-wwqv-p2pp-99h5","primary_source":"","published":"2025-11-07T20:15:21.710Z"},{"affected":"< 2.0.11","affected_versions_present":true,"cve_id":"CVE-2025-64104","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64104","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-30T15:33:07.541Z","patch_url":"","primary_source":"","published":"2025-10-29T18:55:06.129Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"langchain-ai"}}
