{"api_version":"v1","generated_at":"2026-10-08T21:30:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-wproyal-ashe-0436d80e9e1e","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/ashe","name":"Ashe","next_cursor":null,"observations":[{"affected":"\u2264 2.266","affected_versions_present":true,"cve_id":"CVE-2026-39627","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-39627","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-29T09:52:02.867Z","patch_url":"","primary_source":"","published":"2026-04-08T08:30:27.618Z"},{"affected":"\u2264 2.233","affected_versions_present":true,"cve_id":"CVE-2024-37478","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37478","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-28T16:09:59.748Z","patch_url":"","primary_source":"","published":"2025-01-02T12:00:56.190Z"},{"affected":"\u2264 2.243","affected_versions_present":true,"cve_id":"CVE-2024-9777","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-9777","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-08T17:24:25.234Z","patch_url":"https://themes.trac.wordpress.org/changeset/248853/","primary_source":"","published":"2024-11-19T12:45:33.062Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"wproyal"}}
