{"api_version":"v1","generated_at":"2026-10-09T12:35:00+00:00","product":{"cve_count":32,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-zulip-zulip-2a0985ff53ba","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/zulip","name":"zulip","next_cursor":null,"observations":[{"affected":"< 12.0","affected_versions_present":true,"cve_id":"CVE-2026-40300","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40300","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T12:44:55.899Z","patch_url":"","primary_source":"","published":"2026-05-12T16:33:02.829Z"},{"affected":">= 1.4.0, < 11.6","affected_versions_present":true,"cve_id":"CVE-2026-26058","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26058","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-06T13:11:57.089Z","patch_url":"https://github.com/zulip/zulip/commit/2df49e7750ce3fc49ef1d44b1c4ece654d4b754c","primary_source":"","published":"2026-04-03T20:59:08.941Z"},{"affected":"< 11.6","affected_versions_present":true,"cve_id":"CVE-2026-25742","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25742","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-08T18:53:28.819Z","patch_url":"https://github.com/zulip/zulip/commit/3c045414299680b9f5dca7d76cf6cef6121c0236","primary_source":"","published":"2026-04-03T20:12:07.296Z"},{"affected":"< bf28c82dc9b1f630fa8e9106358771b20a0040f7","affected_versions_present":true,"cve_id":"CVE-2026-25741","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-25741","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-03T20:37:43.113Z","patch_url":"","primary_source":"","published":"2026-02-26T21:44:34.398Z"},{"affected":">= 5.0, < 11.5","affected_versions_present":true,"cve_id":"CVE-2026-24050","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24050","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-09T15:28:55.237Z","patch_url":"https://github.com/zulip/zulip/commit/e6093d9e4788f4d82236d856c5ed7b16767886a7","primary_source":"","published":"2026-02-06T18:20:33.160Z"},{"affected":">= 2.0.0-rc1, < 10.4","affected_versions_present":true,"cve_id":"CVE-2025-52559","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52559","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-02T19:37:15.550Z","patch_url":"https://github.com/zulip/zulip/security/advisories/GHSA-vgf2-vw4r-m663","primary_source":"","published":"2025-07-02T19:31:12.064Z"},{"affected":">= 10.0, < 10.3","affected_versions_present":true,"cve_id":"CVE-2025-47930","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-47930","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-16T13:19:46.691Z","patch_url":"https://github.com/zulip/zulip/commit/d2ff4bda4c3efa30fc3ab1f151255cfdbf370f78","primary_source":"","published":"2025-05-15T23:17:29.829Z"},{"affected":"< 10.2","affected_versions_present":true,"cve_id":"CVE-2025-31478","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-31478","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-23T16:42:16.303Z","patch_url":"","primary_source":"","published":"2025-04-16T21:28:23.087Z"},{"affected":">= 1.6.0, < 10.1","affected_versions_present":true,"cve_id":"CVE-2025-30369","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-30369","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-31T18:17:38.643Z","patch_url":"https://github.com/zulip/zulip/security/advisories/GHSA-fcgx-q63f-7gw4","primary_source":"","published":"2025-03-31T16:32:54.301Z"},{"affected":">= 10.0-beta1, < 10.1","affected_versions_present":true,"cve_id":"CVE-2025-30368","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-30368","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-31T18:59:32.854Z","patch_url":"https://github.com/zulip/zulip/security/advisories/GHSA-rmhr-5ffq-qcrc","primary_source":"","published":"2025-03-31T16:26:48.673Z"},{"affected":">= 2.1.0, < 10.0","affected_versions_present":true,"cve_id":"CVE-2025-27149","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27149","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-31T18:36:58.695Z","patch_url":"","primary_source":"","published":"2025-03-31T15:33:38.543Z"},{"affected":">= 50256f48314250978f521ef439cafa704e056539, < 75be449d456d29fef27e9d1828bafa30174284b4","affected_versions_present":true,"cve_id":"CVE-2025-25195","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25195","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-14T15:46:45.940Z","patch_url":"","primary_source":"","published":"2025-02-13T21:47:24.651Z"},{"affected":">= 7.0, < 9.4","affected_versions_present":true,"cve_id":"CVE-2024-56136","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-56136","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-06T21:29:12.118Z","patch_url":"https://github.com/zulip/zulip/commit/c6334a765b1e6d71760e4a3b32ae5b8367f2ed4d","primary_source":"","published":"2025-01-16T19:25:33.261Z"},{"affected":">= 3.0, < 8.3","affected_versions_present":true,"cve_id":"CVE-2024-27286","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27286","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-31T16:30:29.284Z","patch_url":"https://github.com/zulip/zulip/commit/3db1733310ddd944c2e690ba673232345c928eec","primary_source":"","published":"2024-03-20T19:35:59.164Z"},{"affected":"= 8.0","affected_versions_present":true,"cve_id":"CVE-2024-21630","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-21630","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-29T15:19:04.180Z","patch_url":"https://github.com/zulip/zulip/commit/0df7bd71f32f3b772e2646c6ab0d60c9b610addf","primary_source":"","published":"2024-01-25T19:30:09.106Z"},{"affected":">= 1.3.0, < 7.5","affected_versions_present":true,"cve_id":"CVE-2023-47642","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-47642","fixed":"7.5","last_modified":"2024-08-29T14:49:20.515Z","patch_url":"https://github.com/zulip/zulip/commit/6336322d2f9bbccaacfc80cba83a3c62eefd5737","primary_source":"","published":"2023-11-16T21:41:46.646Z"},{"affected":"< 7.3","affected_versions_present":true,"cve_id":"CVE-2023-32678","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32678","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-30T18:17:38.788Z","patch_url":"","primary_source":"","published":"2023-08-25T20:04:49.432Z"},{"affected":">= 7.0-beta1, < 7.0-beta3","affected_versions_present":true,"cve_id":"CVE-2023-33186","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-33186","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-01-10T19:47:40.529Z","patch_url":"https://github.com/zulip/zulip/pull/25370","primary_source":"","published":"2023-05-30T05:31:37.279Z"},{"affected":">= 2.1.0, < 6.2","affected_versions_present":true,"cve_id":"CVE-2023-28623","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28623","fixed":"6.2.","last_modified":"2025-02-12T17:01:30.806Z","patch_url":"https://github.com/zulip/zulip/commit/3df1b4dd7c210c21deb6f829df19412b74573f8d","primary_source":"","published":"2023-05-19T21:04:51.624Z"},{"affected":"> 1.9.0, < 6.2","affected_versions_present":true,"cve_id":"CVE-2023-32677","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32677","fixed":"6.2.","last_modified":"2025-02-12T16:37:08.157Z","patch_url":"https://github.com/zulip/zulip/commit/7c2693a2c64904d1d0af8503b57763943648cbe5","primary_source":"","published":"2023-05-19T20:44:47.105Z"},{"affected":">= 04cf68b, < 2f6c5a8","affected_versions_present":true,"cve_id":"CVE-2023-22735","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22735","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-10T21:15:28.102Z","patch_url":"https://github.com/zulip/zulip/security/advisories/GHSA-wm83-3764-5wqh","primary_source":"","published":"2023-02-07T18:48:29.870Z"},{"affected":">= 5.0, < 5.7","affected_versions_present":true,"cve_id":"CVE-2022-41914","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-41914","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:36:55.819Z","patch_url":"https://github.com/zulip/zulip/commit/59edbfa4113d140d3e20126bc65f4d67b2a8ffe5","primary_source":"","published":"2022-11-16T00:00:00.000Z"},{"affected":"< 5.6","affected_versions_present":true,"cve_id":"CVE-2022-36048","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36048","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T17:46:52.591Z","patch_url":"","primary_source":"","published":"2022-08-31T19:15:11.000Z"},{"affected":"< 5.5","affected_versions_present":true,"cve_id":"CVE-2022-31168","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31168","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T17:57:19.812Z","patch_url":"https://github.com/zulip/zulip/commit/751b2a03e565e9eb02ffe923b7c24ac73d604034","primary_source":"","published":"2022-07-22T13:05:12.000Z"},{"affected":">= 2.1.0, < 5.4","affected_versions_present":true,"cve_id":"CVE-2022-31134","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31134","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:02:59.572Z","patch_url":"","primary_source":"","published":"2022-07-12T20:35:10.000Z"},{"affected":">= 2.1.0, < 5.3","affected_versions_present":true,"cve_id":"CVE-2022-31017","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31017","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:08:41.319Z","patch_url":"","primary_source":"","published":"2022-06-25T08:15:16.000Z"},{"affected":">= 4.0, < 4.11","affected_versions_present":true,"cve_id":"CVE-2022-24751","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24751","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:53:29.799Z","patch_url":"https://github.com/zulip/zulip/commit/62ba8e455d8f460001d9fb486a6dabfd1ed67717","primary_source":"","published":"2022-03-16T13:30:15.000Z"},{"affected":">= 2021-06-03, < 2022-03-01","affected_versions_present":true,"cve_id":"CVE-2022-23656","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-23656","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:59:20.616Z","patch_url":"https://github.com/zulip/zulip/commit/e090027adcbf62737d5b1f83a9618a9500a49321","primary_source":"","published":"2022-03-02T20:25:10.000Z"},{"affected":">= 2.0.0, < 4.10","affected_versions_present":true,"cve_id":"CVE-2022-21706","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-21706","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:00:22.039Z","patch_url":"https://github.com/zulip/zulip/commit/88917019f03860609114082cdc0f31a561503f9e","primary_source":"","published":"2022-02-25T23:25:10.000Z"},{"affected":"< 4.9","affected_versions_present":true,"cve_id":"CVE-2021-43799","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43799","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:09:13.932Z","patch_url":"https://github.com/zulip/zulip/commit/a5496f4098e3998c9b84e8dc564aa983d6cdf6e8","primary_source":"","published":"2022-01-25T20:55:11.000Z"},{"affected":"< 4.8","affected_versions_present":true,"cve_id":"CVE-2021-43791","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43791","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:03:08.967Z","patch_url":"https://github.com/zulip/zulip/commit/a014ef75a3a0ed7f24ebb157632ba58751e732c6","primary_source":"","published":"2021-12-02T00:15:11.000Z"},{"affected":"< 4.7","affected_versions_present":true,"cve_id":"CVE-2021-41115","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41115","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T02:59:31.570Z","patch_url":"https://github.com/zulip/zulip/security/advisories/GHSA-4h36-mqfq-42jg","primary_source":"","published":"2021-10-07T22:20:13.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"zulip"}}
