{
  "@id": "urn:uuid:42cd8fe0-4141-47e4-8a6a-f0b1a036f199",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/schema 3.12.3-tuxcare.5. CVE-2022-25852 is a false positive for this Nuxt.js repository. The CVE affects PostgreSQL database client bindings (pg-native and libpq npm packages), which are unrelated to Nuxt. Exhaustive searches confirmed no presence of pg-native or libpq as the project itself, as vendored/bundled code, or as declared dependencies. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2022-25852"
      },
      "impact_statement": "CVE-2022-25852 is a false positive for this Nuxt.js repository. The CVE affects PostgreSQL database client bindings (pg-native and libpq npm packages), which are unrelated to Nuxt. Exhaustive searches confirmed no presence of pg-native or libpq as the project itself, as vendored/bundled code, or as declared dependencies. This is a wrong-project match."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34343 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2024-34343"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34344 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2024-34344"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-24360 affects version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2025-24360"
      },
      "action_statement": "Vulnerability CVE-2025-24360 affects version 3.12.3-tuxcare.5 of @nuxt/schema."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-24361 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2025-24361"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27415 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2025-27415"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-59414 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2025-59414"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41305 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2026-41305"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/schema 3.12.3-tuxcare.5. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (XSS in Address6 class methods), but this repository is 'nuxt' (a Vue.js framework). The affected component is completely absent from this repository - not as the project itself, not vendored/bundled, and not as any dependency.",
      "vulnerability": {
        "name": "CVE-2026-42338"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (XSS in Address6 class methods), but this repository is 'nuxt' (a Vue.js framework). The affected component is completely absent from this repository - not as the project itself, not vendored/bundled, and not as any dependency."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45669 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-45669"
      },
      "action_statement": "Vulnerability CVE-2026-45669 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46342 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-46342"
      },
      "action_statement": "Vulnerability CVE-2026-46342 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47200 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-47200"
      },
      "action_statement": "Vulnerability CVE-2026-47200 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53721 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "CVE-2026-53721"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53722 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-53722"
      },
      "action_statement": "Vulnerability CVE-2026-53722 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.6."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56317 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.8.",
      "vulnerability": {
        "name": "CVE-2026-56317"
      },
      "action_statement": "Vulnerability CVE-2026-56317 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.8."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56326 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-56326"
      },
      "action_statement": "Vulnerability CVE-2026-56326 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71314 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-71314"
      },
      "action_statement": "Vulnerability CVE-2026-71314 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71316 does not affect version 3.12.3-tuxcare.5 of @nuxt/schema. Nuxt.js 3.12.3 is not affected by CVE-2026-71316. The vulnerability affects versions 4.4.0-4.5.1 and involves runtime cache access that bypasses route middleware. In version 3.12.3, the payload cache mechanism is strictly limited to the prerendering phase - at runtime, payloadCache is null and the import.meta.prerender guard prevents any cache access. The attack path from HTTP requests to /_payload.json endpoints to disclosure of SSR data cannot complete because the intermediate runtime caching step is structurally absent in this version.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-71316"
      },
      "impact_statement": "Nuxt.js 3.12.3 is not affected by CVE-2026-71316. The vulnerability affects versions 4.4.0-4.5.1 and involves runtime cache access that bypasses route middleware. In version 3.12.3, the payload cache mechanism is strictly limited to the prerendering phase - at runtime, payloadCache is null and the import.meta.prerender guard prevents any cache access. The attack path from HTTP requests to /_payload.json endpoints to disclosure of SSR data cannot complete because the intermediate runtime caching step is structurally absent in this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71318 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-71318"
      },
      "action_statement": "Vulnerability CVE-2026-71318 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71320 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-71320"
      },
      "action_statement": "Vulnerability CVE-2026-71320 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71321 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9.",
      "vulnerability": {
        "name": "CVE-2026-71321"
      },
      "action_statement": "Vulnerability CVE-2026-71321 affects version 3.12.3-tuxcare.5 of @nuxt/schema, and is fixed in 3.12.3-tuxcare.9."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c9cv-mq2m-ppp3 is fixed in version 3.12.3-tuxcare.5 of @nuxt/schema.",
      "vulnerability": {
        "name": "GHSA-c9cv-mq2m-ppp3"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/%40nuxt/schema@3.12.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.12.3-tuxcare.5 of @nuxt/schema. not_affected \u2014 Target version 3.12.3-tuxcare.2 uses a fundamentally different architecture (unhead v1 with server-side data-passing) that does not contain the vulnerable code pattern. The CVE vulnerability (GHSA-m3q2-p4fw-w38m) involves innerHTML usage in client-side DOM manipulation, which was introduced later in version 3.16.0 with the unhead v2 upgrade (March 2025). Version 3.12.3 predates this architectur...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-m3q2-p4fw-w38m"
      },
      "impact_statement": "not_affected \u2014 Target version 3.12.3-tuxcare.2 uses a fundamentally different architecture (unhead v1 with server-side data-passing) that does not contain the vulnerable code pattern. The CVE vulnerability (GHSA-m3q2-p4fw-w38m) involves innerHTML usage in client-side DOM manipulation, which was introduced later in version 3.16.0 with the unhead v2 upgrade (March 2025). Version 3.12.3 predates this architectur..."
    }
  ]
}
