{"api_version":"v1","generated_at":"2026-10-07T14:20:00+00:00","product":{"cve_count":16,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-protobufjs-protobuf-js-74ff44efe2ed","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/protobuf.js","name":"protobuf.js","next_cursor":null,"observations":[{"affected":">= 8.2.0, < 8.6.5","affected_versions_present":true,"cve_id":"CVE-2026-59876","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59876","fixed":"8.6.5.","last_modified":"2026-07-09T14:41:45.107Z","patch_url":"https://github.com/protobufjs/protobuf.js/pull/2335","primary_source":"","published":"2026-07-08T15:31:11.421Z"},{"affected":">= 7.5.0, < 7.6.5; >= 8.0.0, < 8.6.6","affected_versions_present":true,"cve_id":"CVE-2026-59877","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59877","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-07-08T15:49:27.814Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-59877","primary_source":"","published":"2026-07-08T15:28:07.696Z"},{"affected":"< 7.6.3; >= 8.0.0, < 8.6.0","affected_versions_present":true,"cve_id":"CVE-2026-54269","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54269","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T16:09:36.165Z","patch_url":"","primary_source":"","published":"2026-06-22T16:23:24.383Z"},{"affected":"< 7.6.1; >= 8.0.0, < 8.4.1","affected_versions_present":true,"cve_id":"CVE-2026-48712","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48712","fixed":"For more about Red Hat Developer Hub, see References links","last_modified":"2026-06-23T15:54:24.472Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-48712","primary_source":"","published":"2026-06-22T16:21:21.506Z"},{"affected":">=8.2.0, < 8.5.0","affected_versions_present":true,"cve_id":"CVE-2026-54270","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54270","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T16:09:51.638Z","patch_url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-94rc-8x27-4472","primary_source":"","published":"2026-06-22T16:19:20.449Z"},{"affected":">= 2.0.0, < 2.0.2; < 1.2.1","affected_versions_present":true,"cve_id":"CVE-2026-44295","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44295","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T18:20:05.652Z","patch_url":"","primary_source":"","published":"2026-05-13T14:50:39.216Z"},{"affected":">= 2.0.0, < 2.0.2; < 1.2.1","affected_versions_present":true,"cve_id":"CVE-2026-42290","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42290","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-18T13:54:57.889Z","patch_url":"","primary_source":"","published":"2026-05-13T14:49:30.030Z"},{"affected":"< 7.5.8; >= 8.0.0, < 8.2.0","affected_versions_present":true,"cve_id":"CVE-2026-45740","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45740","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-13T18:20:12.394Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-45740","primary_source":"","published":"2026-05-13T14:46:02.689Z"},{"affected":"< 7.5.6; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44294","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44294","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T18:34:31.882Z","patch_url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-2pr8-phx7-x9h3","primary_source":"","published":"2026-05-13T14:44:30.474Z"},{"affected":"protobuf.js: < 7.5.6, >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44293","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44293","fixed":"RHSA-2026:34160: Red Hat Ansible Automation Platform 2.6 for RHEL 9","last_modified":"2026-09-09T12:05:01.307Z","patch_url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-66ff-xgx4-vchm","primary_source":"","published":"2026-05-13T14:43:33.342Z"},{"affected":"< 7.5.6; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44292","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44292","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-18T14:01:31.297Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-44292","primary_source":"","published":"2026-05-13T14:42:55.155Z"},{"affected":"< 7.5.6; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44291","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44291","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-13T15:32:06.425Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-44291","primary_source":"","published":"2026-05-13T14:42:13.984Z"},{"affected":"< 7.5.6; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44290","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44290","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-05-14T13:45:12.701Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-44290","primary_source":"","published":"2026-05-13T14:41:15.312Z"},{"affected":"< 7.5.6; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44289","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44289","fixed":"For more about Ansible plugins for Red Hat Developer Hub, see References links","last_modified":"2026-08-28T12:04:26.986Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-44289","primary_source":"","published":"2026-05-13T14:39:09.791Z"},{"affected":"< 7.5.6; >= 8.0.0, < 8.0.2","affected_versions_present":true,"cve_id":"CVE-2026-44288","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44288","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T18:33:51.296Z","patch_url":"","primary_source":"","published":"2026-05-13T14:37:26.624Z"},{"affected":"protobuf.js: < 7.5.5, >= 8.0.0-experimental, < 8.0.1","affected_versions_present":true,"cve_id":"CVE-2026-41242","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41242","fixed":"RHSA-2026:21338: Red Hat Developer Hub 1.8","last_modified":"2026-09-09T12:05:00.268Z","patch_url":"https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75","primary_source":"","published":"2026-04-18T16:18:10.652Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"protobufjs"}}
