{"api_version":"v1","generated_at":"2026-10-08T06:15:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-sporkmonger-addressable-005c3361aafa","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/addressable","name":"addressable","next_cursor":null,"observations":[{"affected":">= 2.3.0, < 2.9.0","affected_versions_present":true,"cve_id":"CVE-2026-35611","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35611","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-09T14:36:18.529Z","patch_url":"https://github.com/sporkmonger/addressable/security/advisories/GHSA-h27x-rffw-24p4","primary_source":"","published":"2026-04-07T16:38:08.707Z"},{"affected":"> 2.3.0, <= 2.7.0","affected_versions_present":true,"cve_id":"CVE-2021-32740","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-32740","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T23:33:54.833Z","patch_url":"https://github.com/sporkmonger/addressable/commit/0d8a3127e35886ce9284810a7f2438bff6b43cbc","primary_source":"","published":"2021-07-06T14:15:12.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"sporkmonger"}}
