{"api_version":"v1","generated_at":"2026-10-07T05:10:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-stacklok-toolhive-0917a298c313","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"toolhive","next_cursor":null,"observations":[{"affected":"toolhive: < 0.30.1; toolhive-studio: < 0.38.0","affected_versions_present":true,"cve_id":"CVE-2026-58197","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58197","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-18T16:51:27.459Z","patch_url":"","primary_source":"","published":"2026-09-18T16:34:55.213Z"},{"affected":"toolhive: < 0.31.0","affected_versions_present":true,"cve_id":"CVE-2026-58196","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58196","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-15T17:27:27.029Z","patch_url":"","primary_source":"","published":"2026-09-15T15:53:45.437Z"},{"affected":"toolhive: < 0.29.1","affected_versions_present":true,"cve_id":"CVE-2026-54450","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54450","fixed":"0.29.1.","last_modified":"2026-09-15T16:13:16.652Z","patch_url":"https://github.com/stacklok/toolhive/security/advisories/GHSA-pph6-vfjv-vpjw","primary_source":"","published":"2026-09-15T15:47:39.377Z"},{"affected":"< 0.0.33","affected_versions_present":true,"cve_id":"CVE-2025-47274","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47274","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-12T22:06:42.029Z","patch_url":"","primary_source":"","published":"2025-05-12T14:57:46.781Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"stacklok"}}
