{"api_version":"v1","generated_at":"2026-10-09T19:10:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-sirv-cdn-and-image-hosting-sirv-5e1a6da686e3","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/sirv","name":"Sirv","next_cursor":null,"observations":[{"affected":"\u2264 7.5.3","affected_versions_present":true,"cve_id":"CVE-2025-46233","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-46233","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:12:36.771Z","patch_url":"","primary_source":"","published":"2025-04-22T09:53:23.959Z"},{"affected":"\u2264 7.2.2","affected_versions_present":true,"cve_id":"CVE-2024-32959","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32959","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:09:42.367Z","patch_url":"","primary_source":"","published":"2024-05-17T09:40:23.092Z"},{"affected":"\u2264 7.2.0","affected_versions_present":true,"cve_id":"CVE-2024-27950","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27950","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-11T20:53:08.163Z","patch_url":"","primary_source":"","published":"2024-03-01T07:46:24.507Z"},{"affected":"\u2264 7.2.0","affected_versions_present":true,"cve_id":"CVE-2024-27949","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27949","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-11T20:53:20.649Z","patch_url":"","primary_source":"","published":"2024-03-01T07:30:26.981Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Sirv CDN and Image Hosting"}}
