{"api_version":"v1","generated_at":"2026-10-06T22:40:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-spring-spring-b6f42eaf1446","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/spring","name":"Spring","next_cursor":null,"observations":[{"affected":"5.3.x < 5.3.42","affected_versions_present":true,"cve_id":"CVE-2024-38828","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-38828","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-09T20:03:35.921Z","patch_url":"","primary_source":"","published":"2024-11-18T03:45:46.542Z"},{"affected":"5.7.x < 5.7.13; 5.8.x < 5.8.15; 6.0.x < 6.0.13; 6.1.x < 6.1.11; 6.2.x < 6.2.7; 6.3.x < 6.3.4","affected_versions_present":true,"cve_id":"CVE-2024-38821","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-38821","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-01-24T20:03:04.932Z","patch_url":"","primary_source":"","published":"2024-10-28T07:06:13.404Z"},{"affected":"5.3.x < 5.3.40; 6.0.x < 6.0.24; 6.1.x < 6.1.13","affected_versions_present":true,"cve_id":"CVE-2024-38816","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-38816","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-18T15:06:29.551Z","patch_url":"","primary_source":"","published":"2024-09-13T06:10:06.598Z"},{"affected":"1.0.x < 1.0.6; 1.1.x < 1.1.6; 1.2.x < 1.2.3","affected_versions_present":true,"cve_id":"CVE-2024-22258","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-22258","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-05T20:31:25.882Z","patch_url":"","primary_source":"","published":"2024-03-20T03:58:13.125Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Spring"}}
