{"api_version":"v1","generated_at":"2026-10-08T12:20:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-shepherdwind-velocity-js-9607da4cc129","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/velocity.js","name":"velocity.js","next_cursor":null,"observations":[{"affected":"velocity.js: < 2.1.7","affected_versions_present":true,"cve_id":"CVE-2026-73649","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-73649","fixed":"2.1.7.","last_modified":"2026-08-14T16:42:31.371Z","patch_url":"https://github.com/shepherdwind/velocity.js/security/advisories/GHSA-7gfh-x38p-prh3","primary_source":"","published":"2026-08-13T18:05:31.929Z"},{"affected":"<= 2.1.5","affected_versions_present":true,"cve_id":"CVE-2026-44966","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44966","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-01T17:08:58.934Z","patch_url":"","primary_source":"","published":"2026-05-26T21:21:29.986Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"shepherdwind"}}
