{"api_version":"v1","generated_at":"2026-10-08T17:35:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-podofo-podofo-fd18b5c409d1","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/podofo","name":"podofo","next_cursor":null,"observations":[{"affected":"podofo: >= 1.0.0, < 1.1.1","affected_versions_present":true,"cve_id":"CVE-2026-54633","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54633","fixed":"1.1.1.","last_modified":"2026-09-22T01:52:46.723Z","patch_url":"https://github.com/podofo/podofo/security/advisories/GHSA-f3j2-7846-h5gg","primary_source":"","published":"2026-09-17T21:36:45.592Z"},{"affected":">= 1.0.0, < 1.0.4","affected_versions_present":true,"cve_id":"CVE-2026-44348","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44348","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T18:00:18.245Z","patch_url":"","primary_source":"","published":"2026-05-14T16:38:45.743Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"podofo"}}
