{"api_version":"v1","generated_at":"2026-10-09T00:45:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-mercurius-js-mercurius-8a2b379965e7","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/mercurius","name":"mercurius","next_cursor":null,"observations":[{"affected":"< 16.8.0","affected_versions_present":true,"cve_id":"CVE-2026-30241","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30241","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-09T20:54:28.446Z","patch_url":"https://github.com/mercurius-js/mercurius/commit/5b56f60f4b0d60780b0ff499a479bd830bdd6986","primary_source":"","published":"2026-03-06T21:15:33.433Z"},{"affected":"< 16.4.0","affected_versions_present":true,"cve_id":"CVE-2025-64166","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64166","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-05T16:34:35.585Z","patch_url":"https://github.com/mercurius-js/mercurius/security/advisories/GHSA-v66j-6wwf-jc57","primary_source":"","published":"2026-03-05T15:31:45.641Z"},{"affected":"< 10.5.0","affected_versions_present":true,"cve_id":"CVE-2023-22477","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22477","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-10T21:31:05.984Z","patch_url":"https://github.com/mercurius-js/mercurius/security/advisories/GHSA-cm8h-q92v-xcfc","primary_source":"","published":"2023-01-09T14:12:24.837Z"},{"affected":">= 8.10.0, < 8.11.2","affected_versions_present":true,"cve_id":"CVE-2021-43801","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43801","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:03:08.899Z","patch_url":"https://github.com/mercurius-js/mercurius/security/advisories/GHSA-273r-rm8g-7f3x","primary_source":"","published":"2021-12-13T19:30:12.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"mercurius-js"}}
