Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY38 SECURITY RECORDS

WSO2

WSO2 API Manager

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2025-5802 15 Sep 2026 WSO2 API Manager: < 3.1.0, 3.1.0 < 3.1.0.354, 3.2.0 < 3.2.0.458, 3.2.0 < 3.2.0.478, 3.2.1 < 3.2.1.96, 4.0.0 < 4.0.0.379, 4.1.0 < 4.1.0.262, 4.2.0 < 4.2.0.200, 4.3.0 < 4.3.0.112, 4.4.0 < 4.4.0.72, 4.5.0 < 4.5.0.55, 4.6.0 < 4.6.0.17; WSO2 API Control Plane: < 4.5.0, 4.5.0 < 4.5.0.56, 4.6.0 < 4.6.0.18; WSO2 Universal Gateway: < 4.5.0, 4.5.0 < 4.5.0.55, 4.6.0 < 4.6.0.17; WSO2 Traffic Manager: < 4.5.0, 4.5.0 < 4.5.0.54, 4.6.0 < 4.6.0.17; WSO2 Identity Server: < 5.10.0, 5.10.0 < 5.10.0.383, 5.11.0 < 5.11.0.430, 6.0.0 < 6.0.0.257, 6.1.0 < 6.1.0.234, 6.1.0 < 6.1.0.257, 7.0.0 < 7.0.0.133, 7.1.0 < 7.1.0.41, 7.2.0 < 7.2.0.3; WSO2 Identity Server as Key Manager: < 5.10.0, 5.10.0 < 5.10.0.374; WSO2 Open Banking AM: < 2.0.0, 2.0.0 < 2.0.0.403; WSO2 Open Banking IAM: < 2.0.0, 2.0.0 < 2.0.0.423; WSO2 Carbon Identity Management Endpoint Util: 5.17.5 < 5.17.5.332, 5.18.187 < 5.18.187.330, 5.23.8 < 5.23.8.213, 5.25.92 < 5.25.92.167, 7.0.78 < 7.0.78.162; WSO2 Carbon Identity Application Authentication Framework: 5.17.5 < 5.17.5.332, 5.18.187 < 5.18.187.330 WSO2 Carbon Identity Management Endpoint Util: x ≤ *; WSO2 Carbon Identity Application Authentication Framework: x ≤ * Update reference ↗
CVE-2026-3416 3 Sep 2026 WSO2 API Manager: < 4.1.0, 4.1.0 < 4.1.0.253, 4.2.0 < 4.2.0.193, 4.3.0 < 4.3.0.104, 4.4.0 < 4.4.0.68, 4.5.0 < 4.5.0.52; WSO2 API Control Plane: 4.5.0 < 4.5.0.53 Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5174/#solution Update reference ↗
CVE-2026-3418 6 Aug 2026 WSO2 API Manager: 4.4.0 < 4.4.0.67, 4.5.0 < 4.5.0.52, 4.6.0 < 4.6.0.16; WSO2 Traffic Manager: 4.5.0 < 4.5.0.51, 4.6.0 < 4.6.0.16; WSO2 API Control Plane: 4.5.0 < 4.5.0.53, 4.6.0 < 4.6.0.17; WSO2 Universal Gateway: 4.5.0 < 4.5.0.52, 4.6.0 < 4.6.0.16; WSO2 Carbon API Management Implementation: 9.30.67 < 9.30.67.156, 9.31.86 < 9.31.86.141, 9.32.147 < 9.32.147.44; WSO2 API Manager Publisher REST API V4: 9.30.67 < 9.30.67.156, 9.31.86 < 9.31.86.141, 9.32.147 < 9.32.147.44; WSO2 Carbon API Management API: 9.30.67 < 9.30.67.156 WSO2 Carbon API Management Implementation: 9.33.104 ≤ *; WSO2 API Manager Publisher REST API V4: 9.33.104 ≤ *; WSO2 Carbon API Management API: 9.33.104 ≤ * Update reference ↗
CVE-2026-3415 6 Aug 2026 WSO2 API Manager: < 3.2.0, 3.2.0 < 3.2.0.472, 3.2.1 < 3.2.1.91, 4.1.0 < 4.1.0.254, 4.2.0 < 4.2.0.194, 4.3.0 < 4.3.0.105, 4.4.0 < 4.4.0.68, 4.5.0 < 4.5.0.53, 4.6.0 < 4.6.0.16; WSO2 Universal Gateway: 4.5.0 < 4.5.0.53, 4.6.0 < 4.6.0.16; WSO2 Traffic Manager: 4.5.0 < 4.5.0.52, 4.6.0 < 4.6.0.16; WSO2 API Control Plane: 4.5.0 < 4.5.0.54, 4.6.0 < 4.6.0.17; WSO2 Carbon API Gateway: 6.7.206 < 6.7.206.594, 6.7.210 < 6.7.210.95, 9.20.74 < 9.20.74.398, 9.28.116 < 9.28.116.412, 9.29.120 < 9.29.120.228, 9.30.67 < 9.30.67.158, 9.31.86 < 9.31.86.147, 9.32.147 < 9.32.147.38; WSO2 Carbon API Management Implementation: 6.7.206 < 6.7.206.594, 6.7.210 < 6.7.210.95, 9.20.74 < 9.20.74.398, 9.28.116 < 9.28.116.412, 9.29.120 < 9.29.120.228, 9.30.67 < 9.30.67.158, 9.31.86 < 9.31.86.147, 9.32.147 < 9.32.147.38 WSO2 Carbon API Gateway: 9.33.61 ≤ *; WSO2 Carbon API Management Implementation: 9.33.61 ≤ * Update reference ↗
CVE-2025-14561 6 Aug 2026 WSO2 API Manager: 4.1.0 < 4.1.0.242, 4.2.0 < 4.2.0.182, 4.3.0 < 4.3.0.93, 4.4.0 < 4.4.0.57, 4.5.0 < 4.5.0.41, 4.6.0 < 4.6.0.6; WSO2 API Control Plane: 4.5.0 < 4.5.0.42, 4.6.0 < 4.6.0.7; WSO2 Traffic Manager: 4.5.0 < 4.5.0.40, 4.6.0 < 4.6.0.6; WSO2 Universal Gateway: 4.5.0 < 4.5.0.40, 4.6.0 < 4.6.0.6; WSO2 Carbon API Management Implementation: 9.20.74 < 9.20.74.388, 9.28.116 < 9.28.116.395, 9.29.120 < 9.29.120.213, 9.30.67 < 9.30.67.135, 9.31.86 < 9.31.86.108, 9.32.147 < 9.32.147.5; WSO2 Carbon API Manager Rest API Utility: 9.20.74 < 9.20.74.388, 9.28.116 < 9.28.116.395, 9.29.120 < 9.29.120.213, 9.30.67 < 9.30.67.135, 9.31.86 < 9.31.86.108, 9.32.147 < 9.32.147.5 WSO2 Carbon API Management Implementation: 9.32.160 ≤ *; WSO2 Carbon API Manager Rest API Utility: 9.32.160 ≤ * Update reference ↗
CVE-2025-6508 6 Aug 2026 WSO2 API Manager: 4.1.0 < 4.1.0.212, 4.2.0 < 4.2.0.183 Follow the instructions given on https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2025-4306/#solution Update reference ↗
CVE-2026-1728 6 Aug 2026 < 4.0.0; 4.0.0 < 4.0.0.384; 4.1.0 < 4.1.0.248; 4.2.0 < 4.2.0.188; 4.3.0 < 4.3.0.99; 4.4.0 < 4.4.0.63; 4.5.0 < 4.5.0.48; 4.6.0 < 4.6.0.12 9.33.27 ≤ * Update reference ↗
CVE-2026-0637 6 Aug 2026 < 3.1.0; 3.1.0 < 3.1.0.357; 3.2.0 < 3.2.0.465; 3.2.1 < 3.2.1.84; 4.1.0 < 4.1.0.249; 4.2.0 < 4.2.0.189; 4.3.0 < 4.3.0.100; 4.4.0 < 4.4.0.64 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-8995 6 Aug 2026 < 3.1.0; 3.1.0 < 3.1.0.320; 3.2.0 < 3.2.0.413; 3.2.1 < 3.2.1.90; 4.0.0 < 4.0.0.334; 4.1.0 < 4.1.0.255; 4.2.0 < 4.2.0.195; 4.3.0 < 4.3.0.106 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-2445 20 Jul 2026 4.2.0 < 4.2.0.195; 4.3.0 < 4.3.0.106; 4.4.0 < 4.4.0.70; 4.5.0 < 4.5.0.55; 4.6.0 < 4.6.0.19; 4.5.0 < 4.5.0.56; 4.6.0 < 4.6.0.20; 6.0.0 < 6.0.0.263 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-1248 4 Jul 2026 < 3.0.0; 3.0.0 < 3.0.0.153; 3.1.0 < 3.1.0.267; 3.2.0 < 3.2.0.351; 4.0.0 < 4.0.0.269; 4.1.0 < 4.1.0.169; < 5.8.0; 5.8.0 < 5.8.0.101 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-2053 26 Jun 2026 < 3.1.0; 3.1.0 < 3.1.0.360; 3.2.0 < 3.2.0.465; 3.2.1 < 3.2.1.84; 4.0.0 < 4.0.0.385; 4.2.0 < 4.2.0.189 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-8154 11 May 2026 < 4.1.0; 4.1.0 < 4.1.0.218; 4.2.0 < 4.2.0.164; 4.3.0 < 4.3.0.74; 4.4.0 < 4.4.0.38; 4.5.0 < 4.5.0.20; 4.5.0 < 4.5.0.19; 4.5.0 < 4.5.0.21 9.32.2 ≤ * Update reference ↗
CVE-2025-6024 16 Apr 2026 < 3.1.0; 3.1.0 < 3.1.0.351; 3.2.0 < 3.2.0.455; 3.2.1 < 3.2.1.74; 4.0.0 < 4.0.0.375; 4.1.0 < 4.1.0.238; < 5.10.0; 5.10.0 < 5.10.0.360 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-10242 16 Apr 2026 < 3.2.0; 3.2.0 < 3.2.0.401; 4.0.0 < 4.0.0.318 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-8010 16 Apr 2026 < 3.2.0; 3.2.0 < 3.2.0.397; 3.2.1 < 3.2.1.27; 4.0.0 < 4.0.0.310; 4.0.0 < 4.0.0.319; 4.1.0 < 4.1.0.171; 4.2.0 < 4.2.0.127; 4.3.0 < 4.3.0.39 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-4867 16 Apr 2026 < 3.2.0; 3.2.0 < 3.2.0.408; 3.2.1 < 3.2.1.32; 4.0.0 < 4.0.0.293; 4.1.0 < 4.1.0.187 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-2374 16 Apr 2026 < 3.1.0; 3.1.0 < 3.1.0.278; 3.2.0 < 3.2.0.368; 4.0.0 < 4.0.0.280; 4.1.0 < 4.1.0.206; 4.2.0 < 4.2.0.144; 4.3.0 < 4.3.0.57; < 5.10.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-1524 24 Feb 2026 4.2.0 < 4.2.0.108; 6.0.0 < 6.0.0.171; 6.1.0 < 6.1.0.128 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-13590 19 Feb 2026 WSO2 API Manager: 4.2.0 < 4.2.0.179, 4.3.0 < 4.3.0.91, 4.4.0 < 4.4.0.55, 4.5.0 < 4.5.0.38, 4.6.0 < 4.6.0.3; WSO2 API Control Plane: < 4.5.0, 4.5.0 < 4.5.0.39, 4.6.0 < 4.6.0.3; WSO2 Universal Gateway: < 4.5.0, 4.5.0 < 4.5.0.37, 4.6.0 < 4.6.0.3; WSO2 Traffic Manager: < 4.5.0, 4.5.0 < 4.5.0.37, 4.6.0 < 4.6.0.3; org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl: 9.28.116 < 9.28.116.391, 9.29.120 < 9.29.120.210, 9.30.67 < 9.30.67.133, 9.31.86 < 9.31.86.100, 9.32.147 < 9.32.147.2 WSO2 API Manager: < 4.2.0; org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.impl: 9.32.167 ≤ * Update reference ↗
CVE-2025-9312 18 Nov 2025 < 2.2.0; 2.2.0 < 2.2.0.58; 2.5.0 < 2.5.0.84; 2.6.0 < 2.6.0.145; 3.0.0 < 3.0.0.175; 3.1.0 < 3.1.0.339; 3.2.0 < 3.2.0.439; 3.2.1 < 3.2.1.59 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-10907 5 Nov 2025 < 3.1.0; 3.1.0 < 3.1.0.345; 3.2.0 < 3.2.0.448; 3.2.1 < 3.2.1.66; 4.0.0 < 4.0.0.367; 4.1.0 < 4.1.0.230; 4.2.0 < 4.2.0.169; 4.3.0 < 4.3.0.81 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-9152 16 Oct 2025 < 3.2.0; 3.2.0 < 3.2.0.437; 3.2.1 < 3.2.1.57; 4.0.0 < 4.0.0.357; 4.1.0 < 4.1.0.221; 4.2.0 < 4.2.0.159; 4.3.0 < 4.3.0.72; 4.4.0 < 4.4.0.35 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-10611 16 Oct 2025 < 2.1.0; 2.1.0 < 2.1.0.42; 2.2.0 < 2.2.0.61; 2.5.0 < 2.5.0.87; 2.6.0 < 2.6.0.148; 3.0.0 < 3.0.0.178; 3.1.0 < 3.1.0.345; 3.2.0 < 3.2.0.446 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-5717 23 Sep 2025 < 3.0.0; 3.0.0 < 3.0.0.174; 3.1.0 < 3.1.0.330; 3.2.0 < 3.2.0.426; 3.2.1 < 3.2.1.46; 4.0.0 < 4.0.0.344; 4.1.0 < 4.1.0.208; 4.2.0 < 4.2.0.147 3.2.15 ≤ * Update reference ↗
CVE-2025-4760 23 Sep 2025 < 3.2.0; 3.2.0 < 3.2.0.428; 3.2.1 < 3.2.1.48; 4.1.0 < 4.1.0.209; 4.2.0 < 4.2.0.145; 4.3.0 < 4.3.0.60; 4.4.0 < 4.4.0.23; 4.5.0 < 4.5.0.7 9.31.117 ≤ * Update reference ↗
CVE-2024-4598 23 Sep 2025 < 3.2.0; 3.2.0 < 3.2.0.422; 3.2.1 < 3.2.1.42; 4.1.0 < 4.1.0.152; 4.3.0 < 4.3.0.55; < 1.2.0; 1.2.0 < 1.2.0.157; 4.1.0 < 4.1.0.95 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-5962 22 May 2025 4.2.0 < 4.2.0.94; 4.3.0 < 4.3.0.9; 6.0.0 < 6.0.0.199; 6.1.0 < 6.1.0.172 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-6914 22 May 2025 < 2.2.0; 2.2.0 < 2.2.0.55; 2.5.0 < 2.5.0.82; 2.6.0 < 2.6.0.141; 3.0.0 < 3.0.0.161; 3.1.0 < 3.1.0.292; 3.2.0 < 3.2.0.382; 3.2.1 < 3.2.1.14 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-2905 5 May 2025 < 2.0.0; 2.1.0; 2.2.0; 2.5.0; 2.6.0; 3.0.0; 3.1.0; 4.0.0 < 4.0.0.311 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-5848 27 Feb 2025 < 3.1.0; 3.1.0 < 3.1.0.285; 3.2.0 < 3.2.0.375; 3.2.1 < 3.2.1.10; 4.0.0 < 4.0.0.300; 4.1.0 < 4.1.0.160; 4.2.0 < 4.2.0.92; 4.3.0 < 4.3.0.10 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-2321 27 Feb 2025 < 3.0.0; 4.0.0 < 4.0.0.275; 4.1.0 < 4.1.0.153; 4.2.0 < 4.2.0.83; < 5.9.0; 5.11.0 < 5.11.0.326; 6.0.0 < 6.0.0.172; 6.1.0 < 6.1.0.130 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-6911 18 Dec 2023 < 2.2.0.0; 2.2.0.0 < 2.2.0.1; 2.5.0.0 < 2.5.0.1; 2.6.0.0 < 2.6.0.1; 3.0.0.0 < 3.0.0.1; 3.1.0.0 < 3.1.0.1; 3.2.0.0 < 3.2.0.1; < 3.2.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-6839 15 Dec 2023 < 3.0.0.0; 3.0.0.0 < 3.0.0.15; 3.2.0.0 < 3.2.0.32 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-6838 15 Dec 2023 < 3.1.0.0; 3.1.0.0 < 3.1.0.14; 3.2.0.0 < 3.2.0.10; < 5.10.0.0; 5.10.0.0 < 5.10.0.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-6837 15 Dec 2023 < 2.5.0; 2.5.0 < 2.5.0.32; 2.6.0 < 2.6.0.52; 3.0.0 < 3.0.0.50; 3.1.0 < 3.1.0.72; 3.2.0 < 3.2.0.86; 4.0.0 < 4.0.0.35; < 5.6.0 5.20.254 ≤ * Update reference ↗
CVE-2023-6836 15 Dec 2023 < 3.0.0.0; 3.0.0.0 < 3.0.0.1; < 2.2.0.0; 2.2.0.0 < 2.2.0.1; 2.5.0.0 < 2.5.0.1; < 6.0.0.2; 6.0.0.0 < 6.0.0.3; 6.1.0.0 < 6.1.0.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-6835 15 Dec 2023 < 2.2.0.0; 2.2.0.0 < 2.2.0.16; 2.5.0.0 < 2.5.0.17; 2.6.0.0 < 2.6.0.24; < 3.3.1.0; 3.3.1.0 < 3.3.1.17 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.