Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY5 SECURITY RECORDS

ash-project

ash sql

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-77454 30 Aug 2026 ash sql: 0.4.1 < 0.7.1, e26a63b29bd7501505fafd726f14262cdc3b6629 < 865fdd4e5e70724a23b19c048e6768c31d2209ab No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-81316 30 Aug 2026 ash sql: 0.1.0 < 0.7.1, dd092ed273dec7bd2194352f24a39229fc8ae68b < 4b95468e5434a3526571414219719c9518be6694 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-81318 30 Aug 2026 ash sql: 0.1.0 < 0.7.1, dd092ed273dec7bd2194352f24a39229fc8ae68b < 3d95478cc9e1d5bfaf6144fe9b9793f29e5ab889 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-78691 30 Aug 2026 ash sql: 0.1.1-rc.10 < 0.7.1, cfc7da474c5be2190fd62664a83a689377a8d512 < d95c55c64b1b42cc2fd30211a4913f3145156cd4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-80227 30 Aug 2026 ash sql: 0.1.0 < 0.7.1, dd092ed273dec7bd2194352f24a39229fc8ae68b < 1b11b5d8bc5321e2e6acac21594ef08f61986117 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.