{"api_version":"v1","generated_at":"2026-10-10T02:15:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-publisher-not-identified-putil-merge-0d0e9fe62244","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/putil-merge","name":"putil-merge","next_cursor":null,"observations":[{"affected":"unspecified < 3.8.0","affected_versions_present":true,"cve_id":"CVE-2021-23470","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-23470","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-16T23:32:07.792Z","patch_url":"https://github.com/panates/putil-merge/commit/476d00078dfb2827d7c9ee0f2392c81b864f7bc5","primary_source":"","published":"2022-02-04T20:05:12.083Z"},{"affected":"3.6.6, 3.6.5, 3.6.4, 3.6.3, 3.6.2, 3.6.1, 3.6.0, 3.5.2, 3.5.1, 3.5.0, 3.4.2, 3.4.1, 3.3.0, 3.2.0, 3.1.4, 3.1.3, 3.1.2, 3.1.1, 3.1.0, 3.0.0, 2.2.0, 2.1.0, 2.0.2, 2.0.1, 2.0.0, 1.2.0, 1.1.5, 1.1.4, 1.1.3, 1.1.2, 1.1.1, 1.1.0, 1.0.2, 1.0.1, 1.0.0","affected_versions_present":true,"cve_id":"CVE-2021-25953","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-25953","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T20:19:18.976Z","patch_url":"","primary_source":"","published":"2021-07-14T10:34:46.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Publisher not identified"}}
