{"api_version":"v1","generated_at":"2026-10-07T10:40:00+00:00","product":{"cve_count":8,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-libp2p-js-libp2p-d0177bcb52e2","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"js-libp2p","next_cursor":null,"observations":[{"affected":"js-libp2p: < 11.0.26; floodsub: < 11.0.26","affected_versions_present":true,"cve_id":"CVE-2026-86040","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86040","fixed":"11.0.26.","last_modified":"2026-09-17T19:19:11.341Z","patch_url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-cvfg-hcf3-ggwv","primary_source":"","published":"2026-09-17T15:20:40.724Z"},{"affected":"js-libp2p: >= 8.0.0, < 12.0.24","affected_versions_present":true,"cve_id":"CVE-2026-86039","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86039","fixed":"12.0.24.","last_modified":"2026-09-21T20:48:54.323Z","patch_url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-vrf4-mx87-p53w","primary_source":"","published":"2026-09-17T15:19:00.697Z"},{"affected":"js-libp2p: >= 15.0.0, < 16.0.5","affected_versions_present":true,"cve_id":"CVE-2026-86038","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86038","fixed":"16.0.5.","last_modified":"2026-09-17T17:24:35.905Z","patch_url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-c3gv-825q-fvmp","primary_source":"","published":"2026-09-17T15:16:57.882Z"},{"affected":">= 2.1.5, < 4.2.9","affected_versions_present":true,"cve_id":"CVE-2026-77384","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-77384","fixed":"4.2.9.","last_modified":"2026-08-25T19:04:25.322Z","patch_url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-x787-gh7p-hmq7","primary_source":"","published":"2026-08-24T21:06:39.909Z"},{"affected":"< 16.0.0","affected_versions_present":true,"cve_id":"CVE-2026-49866","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-49866","fixed":"16.0.0.","last_modified":"2026-07-09T14:40:44.919Z","patch_url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-cwc9-cp4j-mcvv","primary_source":"","published":"2026-07-08T20:47:09.051Z"},{"affected":"< 16.2.6","affected_versions_present":true,"cve_id":"CVE-2026-45783","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45783","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T16:14:58.869Z","patch_url":"","primary_source":"","published":"2026-06-10T21:09:40.499Z"},{"affected":"< 15.0.23","affected_versions_present":true,"cve_id":"CVE-2026-46679","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46679","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-11T14:18:41.039Z","patch_url":"","primary_source":"","published":"2026-06-10T21:08:52.464Z"},{"affected":"< 0.38.0","affected_versions_present":true,"cve_id":"CVE-2022-23487","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23487","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T16:31:42.214Z","patch_url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-f44q-634c-jvwv","primary_source":"","published":"2022-12-07T20:05:35.319Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"libp2p"}}
