{"api_version":"v1","generated_at":"2026-10-09T08:05:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-lestrrat-go-jwx-761288eebae0","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/jwx","name":"jwx","next_cursor":null,"observations":[{"affected":">= 2.0.0, < 2.0.21; >= 1.2.0, < 1.2.29","affected_versions_present":true,"cve_id":"CVE-2024-28122","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28122","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-16T15:49:42.161Z","patch_url":"","primary_source":"","published":"2024-03-09T00:45:50.129Z"},{"affected":">= 2.0.0, < 2.0.19; >= 1.0.8, < 1.2.28","affected_versions_present":true,"cve_id":"CVE-2024-21664","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-21664","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-17T20:59:10.877Z","patch_url":"https://github.com/lestrrat-go/jwx/commit/0e8802ce6842625845d651456493e7c87625601f","primary_source":"","published":"2024-01-09T19:18:03.742Z"},{"affected":"< 1.2.27; >= 2.0.0, < 2.0.18","affected_versions_present":true,"cve_id":"CVE-2023-49290","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49290","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-29T13:39:54.272Z","patch_url":"https://github.com/lestrrat-go/jwx/commit/64f2a229b8e18605f47361d292b526bdc4aee01c","primary_source":"","published":"2023-12-04T23:42:53.061Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"lestrrat-go"}}
