{"api_version":"v1","generated_at":"2026-10-09T14:40:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-publisher-not-identified-uppy-d1e6ef1cab97","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/uppy","name":"uppy","next_cursor":null,"observations":[{"affected":"Fixed Versions: 1.13.2, 2.0.0-alpha.5","affected_versions_present":true,"cve_id":"CVE-2020-8205","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8205","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T09:56:27.599Z","patch_url":"","primary_source":"","published":"2020-07-20T15:00:53.000Z"},{"affected":"Fixed Version: 1.9.3","affected_versions_present":true,"cve_id":"CVE-2020-8135","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-8135","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T09:48:25.652Z","patch_url":"https://hackerone.com/reports/786956","primary_source":"","published":"2020-03-20T18:26:32.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Publisher not identified"}}
