{"api_version":"v1","generated_at":"2026-10-05T04:30:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-modelcontextprotocol-rust-sdk-4489e0d2a3e7","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"rust-sdk","next_cursor":null,"observations":[{"affected":"rust-sdk: < 2.1.0","affected_versions_present":true,"cve_id":"CVE-2026-64684","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-64684","fixed":"2.1.0.","last_modified":"2026-09-19T01:56:51.763Z","patch_url":"https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-9g45-5xwm-f3wc","primary_source":"","published":"2026-09-16T21:18:48.886Z"},{"affected":"rust-sdk: < 2.0.0","affected_versions_present":true,"cve_id":"CVE-2026-63127","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63127","fixed":"2.0.0.","last_modified":"2026-09-16T15:39:26.956Z","patch_url":"https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-33f5-2c5q-wgwj","primary_source":"","published":"2026-09-16T14:50:54.296Z"},{"affected":"rust-sdk: < 2.0.0","affected_versions_present":true,"cve_id":"CVE-2026-63128","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63128","fixed":"2.0.0.","last_modified":"2026-09-16T15:18:37.976Z","patch_url":"https://github.com/modelcontextprotocol/rust-sdk/security/advisories/GHSA-9pj6-vhgr-3mwh","primary_source":"","published":"2026-09-16T14:49:04.401Z"},{"affected":"< 1.4.0","affected_versions_present":true,"cve_id":"CVE-2026-42559","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42559","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T16:00:33.149Z","patch_url":"","primary_source":"","published":"2026-05-14T14:24:56.090Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"modelcontextprotocol"}}
