{"api_version":"v1","generated_at":"2026-10-08T22:45:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-zalando-skipper-840e0ed45a10","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/skipper","name":"skipper","next_cursor":null,"observations":[{"affected":"skipper: < 0.27.37","affected_versions_present":true,"cve_id":"CVE-2026-86043","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86043","fixed":"0.27.37.","last_modified":"2026-09-16T19:38:17.894Z","patch_url":"https://github.com/zalando/skipper/security/advisories/GHSA-5gpm-rgj3-9q76","primary_source":"","published":"2026-09-16T18:51:20.486Z"},{"affected":"skipper: < 0.26.22","affected_versions_present":true,"cve_id":"CVE-2026-54247","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54247","fixed":"0.26.22.","last_modified":"2026-09-16T16:19:12.336Z","patch_url":"https://github.com/zalando/skipper/security/advisories/GHSA-cwxq-rc9x-2jvv","primary_source":"","published":"2026-09-14T20:04:06.550Z"},{"affected":"skipper: < 0.27.13","affected_versions_present":true,"cve_id":"CVE-2026-54246","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54246","fixed":"0.27.13.","last_modified":"2026-09-15T14:38:38.620Z","patch_url":"https://github.com/zalando/skipper/security/advisories/GHSA-5587-2x54-jj6h","primary_source":"","published":"2026-09-14T20:03:14.613Z"},{"affected":"skipper: < 0.27.35","affected_versions_present":true,"cve_id":"CVE-2026-65838","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65838","fixed":"0.27.35.","last_modified":"2026-09-15T13:55:41.273Z","patch_url":"https://github.com/zalando/skipper/security/advisories/GHSA-8qqm-fp2q-v734","primary_source":"","published":"2026-09-14T20:01:27.862Z"},{"affected":"See the vendor and CVE records for the affected range.","affected_versions_present":false,"cve_id":"CVE-2026-65604","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-65604","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-24T14:04:07.992Z","patch_url":"","primary_source":"","published":"2026-07-23T21:16:47.608Z"},{"affected":"< 0.26.10","affected_versions_present":true,"cve_id":"CVE-2026-50197","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-50197","fixed":"0.26.10.","last_modified":"2026-07-20T14:33:29.442Z","patch_url":"https://github.com/zalando/skipper/security/advisories/GHSA-659f-rgp5-w4wf","primary_source":"","published":"2026-07-17T19:23:43.574Z"},{"affected":"< 0.24.0","affected_versions_present":true,"cve_id":"CVE-2026-24470","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24470","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-27T14:51:35.229Z","patch_url":"https://github.com/zalando/skipper/commit/a4c87ce029a58eb8e1c2c1f93049194a39cf6219","primary_source":"","published":"2026-01-26T22:23:43.325Z"},{"affected":"< 0.23.0","affected_versions_present":true,"cve_id":"CVE-2026-23742","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23742","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-16T20:24:12.702Z","patch_url":"https://github.com/zalando/skipper/commit/0b52894570773b29e2f3c571b94b4211ef8fa714","primary_source":"","published":"2026-01-16T20:07:46.746Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"zalando"}}
