{"api_version":"v1","generated_at":"2026-10-08T16:50:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-meta-react-server-dom-turbopack-9445143de8a1","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/react-server-dom-turbopack","name":"react-server-dom-turbopack","next_cursor":null,"observations":[{"affected":"19.0.0 \u2264 19.0.7; 19.1.0 \u2264 19.1.8; 19.2.0 \u2264 19.2.7","affected_versions_present":true,"cve_id":"CVE-2026-44907","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44907","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-21T17:22:34.411Z","patch_url":"","primary_source":"","published":"2026-07-21T16:03:32.256Z"},{"affected":"19.0.0 \u2264 19.0.5; 19.1.0 \u2264 19.1.6; 19.2.0 \u2264 19.2.5","affected_versions_present":true,"cve_id":"CVE-2026-23870","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23870","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-06T19:06:00.435Z","patch_url":"","primary_source":"","published":"2026-05-06T16:24:55.620Z"},{"affected":"19.0.0 \u2264 19.0.4; 19.1.0 \u2264 19.1.5; 19.2.0 \u2264 19.2.4","affected_versions_present":true,"cve_id":"CVE-2026-23869","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23869","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:17:57.169Z","patch_url":"","primary_source":"","published":"2026-04-08T19:11:08.418Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Meta"}}
