{"api_version":"v1","generated_at":"2026-10-09T13:45:00+00:00","product":{"cve_count":10,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-mtrudel-bandit-5564186c73c1","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/bandit","name":"bandit","next_cursor":null,"observations":[{"affected":"1.4.0 < 1.12.5; fff06efe3be962b484bd4d3eb339372fda5a231f < d38cf046c9a3cae4d0f88001c2ceb4143f86366b","affected_versions_present":true,"cve_id":"CVE-2026-75484","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75484","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T19:52:42.954Z","patch_url":"","primary_source":"","published":"2026-08-20T21:11:27.523Z"},{"affected":"0.3.4 < 1.12.5; 6feadb31189d18b7dcda6c663112cd3bbaf63a46 < f6914aad14bb1365dd6f306aa592cfb0819bed3e","affected_versions_present":true,"cve_id":"CVE-2026-74836","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-74836","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T19:55:01.929Z","patch_url":"","primary_source":"","published":"2026-08-20T21:11:18.999Z"},{"affected":"1.11.0 < 1.12.1; 21612c7c7b1ce43eccd36d3af3a2299d23513667 < 418ef7e906192a230ddba112f7a669c87b6b0e3a","affected_versions_present":true,"cve_id":"CVE-2026-65623","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65623","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-25T04:16:42.726Z","patch_url":"","primary_source":"","published":"2026-07-24T16:32:24.923Z"},{"affected":"1.6.1 < 1.11.1; e73e379ab59840e8561b5730878f16e29ab06217 < ae3520dfdbfab115c638f8c7f6f6b805db34e1ab","affected_versions_present":true,"cve_id":"CVE-2026-39806","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39806","fixed":"HPE Aruba Networking recommends upgrading the software to the following version: - HPE Aruba Networking Private 5G Core 1.26.1.1 and above NOTE: HPE Aruba Networking does not evaluate or patch HPE Aruba Networking Private 5G Core Software versions that have reached their End of Support (EoS) milestone. For more information about HPE Aruba Networking Telco Product Lifecycle and versioning policy, please visit: https://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow","last_modified":"2026-05-27T15:41:42.286Z","patch_url":"https://www.hpe.com/psnow/doc/a00143052enw","primary_source":"","published":"2026-05-13T13:36:17.806Z"},{"affected":"1.4.0 < 1.11.1; 903e209a521bc216b9f9065c01ae9a0cac2d5a10 < ae3520dfdbfab115c638f8c7f6f6b805db34e1ab","affected_versions_present":true,"cve_id":"CVE-2026-39803","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39803","fixed":"HPE Aruba Networking recommends upgrading the software to the following version: - HPE Aruba Networking Private 5G Core 1.26.1.1 and above NOTE: HPE Aruba Networking does not evaluate or patch HPE Aruba Networking Private 5G Core Software versions that have reached their End of Support (EoS) milestone. For more information about HPE Aruba Networking Telco Product Lifecycle and versioning policy, please visit: https://www.hpe.com/psnow/doc/4aa5-5978enw?jumpid=in_pdfviewer-psnow","last_modified":"2026-05-27T15:40:37.538Z","patch_url":"https://www.hpe.com/psnow/doc/a00143052enw","primary_source":"","published":"2026-05-13T13:36:09.648Z"},{"affected":"0.1.0 < 1.11.0; 7bc8d97cd22697c299baa8012b7f419a7606a80c < f2ca636eb6df385219957e8934e9fc6efa1630d1","affected_versions_present":true,"cve_id":"CVE-2026-39805","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39805","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-24T14:16:00.658Z","patch_url":"","primary_source":"","published":"2026-05-01T20:34:29.400Z"},{"affected":"0.5.9 < 1.11.0; da4027cff7d2b80319e76fe7a32f84beceec490a < 8156921a51e684a951221da7bc30a70a022f722e","affected_versions_present":true,"cve_id":"CVE-2026-39804","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39804","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T15:41:26.362Z","patch_url":"","primary_source":"","published":"2026-05-01T20:34:24.604Z"},{"affected":"1.0.0 < 1.11.0; ff2f829326cd5dcf7335939aef9775269d881e28 < 45feea20dea8af7ffd7245271107b695c040e667","affected_versions_present":true,"cve_id":"CVE-2026-39807","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39807","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T15:41:35.917Z","patch_url":"","primary_source":"","published":"2026-05-01T20:34:22.832Z"},{"affected":"0.5.0 < 1.11.0; 8909391f486d42138c5308410bc5ea49a65f4d46 < 21612c7c7b1ce43eccd36d3af3a2299d23513667","affected_versions_present":true,"cve_id":"CVE-2026-42786","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42786","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T15:41:06.211Z","patch_url":"","primary_source":"","published":"2026-05-01T20:34:17.014Z"},{"affected":"0.3.6 < 1.11.0; f00dd69a5b2a4863be585907acd853c4ffd41399 < 1e8e55966da9129016b73d32f0e1df4630e3b463","affected_versions_present":true,"cve_id":"CVE-2026-42788","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42788","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-27T15:40:29.557Z","patch_url":"","primary_source":"","published":"2026-05-01T20:34:11.911Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"mtrudel"}}
