Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY13 SECURITY RECORDS

ZenHive

mpp

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at mpp, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-87119 22 Sep 2026 mpp: 0.14.0 < 0.16.2, db464dfa9a86ccda58f0827101f6da6bd8aafa78 < 4b6eaec02af0e8485cfb4ff68f467d075ed5dd6f No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-89420 22 Sep 2026 mpp: 0.14.0 < 0.16.2, 82df569c898be1137189e3648e1edb4af6363651 < 7270edc1dcfb58250cc5ee812876609206564165 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-88255 16 Sep 2026 mpp: 0.2.0 < 0.16.2, f8904666061fbab695874856d8fcd02c471dfe1b < e12bd4a1cea2e97c2a01fc059c48e5594a7b4a43 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-89186 16 Sep 2026 mpp: 0.1.0 < 0.16.2, 2d4d1d94aae7790ae0623063961adbeef171fa71 < 2fd91a5ecbd0b0ad2a4ac202b79659e8126dbc0b No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82750 6 Sep 2026 0.2.0 < 0.16.1; d29d54e507918db00a5b65d90136b73166c017d7 < 0482572b47e1ffe1537ab80ab613d47b92833c2d No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-82751 6 Sep 2026 0.2.0 < 0.16.1; d29d54e507918db00a5b65d90136b73166c017d7 < 0482572b47e1ffe1537ab80ab613d47b92833c2d No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-67581 19 Aug 2026 0.3.0 < 0.6.3; 65b9e425ce27631c786a5b380b5e4c5ae607ec6d < ecc038088b1cda09ad8a84acc6cc112addb4a68f An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-73541 19 Aug 2026 0.2.0 < 0.12.0; d29d54e507918db00a5b65d90136b73166c017d7 < ddc46868fba57ccebb567c04709812b466123076 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-73136 19 Aug 2026 0.6.1 < 0.6.4; 542a525563c2fcedd670b593437deca81c6797a4 < 2207d7f456ae14c1d3fcacc6f635bf4f8cee1a34 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-73829 19 Aug 2026 0.2.0 < 0.6.1; f8904666061fbab695874856d8fcd02c471dfe1b < 46c5b0e1311da7d92190dc7d9ea89027a1d365e9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2026-59252 17 Jul 2026 0.2.0 < 0.6.0; d29d54e507918db00a5b65d90136b73166c017d7 < d84e3e528db39654540c2035ea0fbdf7b950d3d1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-59694 17 Jul 2026 0.2.0 < 0.6.0; d29d54e507918db00a5b65d90136b73166c017d7 < 5d6338e2334084c5f2a78cfcca474830733ed7e8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-59695 17 Jul 2026 0.2.0 < 0.6.0; d29d54e507918db00a5b65d90136b73166c017d7 < 5d6338e2334084c5f2a78cfcca474830733ed7e8 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.