{"api_version":"v1","generated_at":"2026-10-09T11:15:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-sbt-sbt-f3344d0b43f3","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/sbt","name":"sbt","next_cursor":null,"observations":[{"affected":">= 0.9.5, < 1.12.7","affected_versions_present":true,"cve_id":"CVE-2026-32948","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32948","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-26T13:21:23.354Z","patch_url":"https://github.com/sbt/sbt/commit/1ce945b6b79cbe3cef6c0fe9efbbd2904e0f479e","primary_source":"","published":"2026-03-24T18:48:30.620Z"},{"affected":">= 0.3.4, < 1.9.7","affected_versions_present":true,"cve_id":"CVE-2023-46122","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-46122","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T13:45:20.258Z","patch_url":"https://github.com/sbt/sbt/security/advisories/GHSA-h9mw-grgx-2fhf","primary_source":"","published":"2023-10-23T15:51:02.875Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"sbt"}}
