{"api_version":"v1","generated_at":"2026-10-08T17:15:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-surfer-surfer-247417099613","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/surfer","name":"Surfer","next_cursor":null,"observations":[{"affected":"\u2264 1.6.4.574","affected_versions_present":true,"cve_id":"CVE-2025-58603","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-58603","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-12T00:38:49.549Z","patch_url":"","primary_source":"","published":"2025-09-03T14:36:41.143Z"},{"affected":"\u2264 1.3.2.357","affected_versions_present":true,"cve_id":"CVE-2023-35037","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35037","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T09:51:49.165Z","patch_url":"","primary_source":"","published":"2024-12-13T14:23:38.299Z"},{"affected":"\u2264 1.5.0.502","affected_versions_present":true,"cve_id":"CVE-2024-49299","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-49299","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:10:24.858Z","patch_url":"","primary_source":"","published":"2024-10-17T17:27:56.653Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Surfer"}}
