{"api_version":"v1","generated_at":"2026-10-09T10:05:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-publisher-not-identified-ecs-02bd2b4915e8","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/ecs","name":"ECS","next_cursor":null,"observations":[{"affected":"< 4.3.10","affected_versions_present":true,"cve_id":"CVE-2026-19613","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-19613","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T20:23:24.079Z","patch_url":"","primary_source":"","published":"2026-08-16T06:00:15.668Z"},{"affected":"< 4.3.8","affected_versions_present":true,"cve_id":"CVE-2026-18807","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-18807","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T20:34:02.880Z","patch_url":"","primary_source":"","published":"2026-08-15T06:00:15.159Z"},{"affected":"< 4.3.8","affected_versions_present":true,"cve_id":"CVE-2026-14230","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14230","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T20:40:06.972Z","patch_url":"","primary_source":"","published":"2026-08-15T06:00:14.469Z"},{"affected":"< 4.3.8","affected_versions_present":true,"cve_id":"CVE-2026-14229","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-14229","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-17T20:41:10.110Z","patch_url":"","primary_source":"","published":"2026-08-15T06:00:14.296Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Publisher not identified"}}
