{"api_version":"v1","generated_at":"2026-10-08T03:10:00+00:00","product":{"cve_count":7,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-sveltejs-devalue-9412c35669b0","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/devalue","name":"devalue","next_cursor":null,"observations":[{"affected":"devalue: >= 5.1.0, < 5.9.3","affected_versions_present":true,"cve_id":"CVE-2026-92708","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-92708","fixed":"5.9.3.","last_modified":"2026-09-23T19:38:36.551Z","patch_url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-j22f-vq7h-c4qm","primary_source":"","published":"2026-09-18T19:54:28.335Z"},{"affected":"devalue: < 5.9.2","affected_versions_present":true,"cve_id":"CVE-2026-81176","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-81176","fixed":"5.9.2.","last_modified":"2026-09-17T19:25:51.846Z","patch_url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-9rgm-9g3h-6x36","primary_source":"","published":"2026-09-16T18:34:34.881Z"},{"affected":">= 5.6.3, < 5.8.1","affected_versions_present":true,"cve_id":"CVE-2026-42570","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42570","fixed":"For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258","last_modified":"2026-08-24T12:07:13.887Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42570","primary_source":"","published":"2026-06-09T16:12:26.377Z"},{"affected":"< 5.6.4","affected_versions_present":true,"cve_id":"CVE-2026-30226","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-30226","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-12T13:51:34.208Z","patch_url":"","primary_source":"","published":"2026-03-11T17:47:40.016Z"},{"affected":">= 5.1.0, < 5.6.2","affected_versions_present":true,"cve_id":"CVE-2026-22775","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22775","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:19:19.060Z","patch_url":"https://github.com/sveltejs/devalue/commit/11755849fa0634ae294a15ec0aef2f43efcad7c4","primary_source":"","published":"2026-01-15T18:59:37.499Z"},{"affected":">= 5.3.0, < 5.6.2","affected_versions_present":true,"cve_id":"CVE-2026-22774","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22774","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T01:19:21.983Z","patch_url":"https://github.com/sveltejs/devalue/commit/e46afa64dd2b25aa35fb905ba5d20cea63aabbf7","primary_source":"","published":"2026-01-15T18:53:21.963Z"},{"affected":"< 5.3.2","affected_versions_present":true,"cve_id":"CVE-2025-57820","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-57820","fixed":"5.3.2","last_modified":"2025-08-27T20:42:46.786Z","patch_url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-vj54-72f3-p5jv","primary_source":"","published":"2025-08-26T22:33:19.100Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"sveltejs"}}
