{
  "@id": "urn:uuid:c83acf8b-cfb7-42f8-9a7c-07265b315560",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T09:35:37.868583+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-28168 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2020-28168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3749 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2021-3749"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45857 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2023-45857"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-30T09:35:37.868583+00:00",
      "status_notes": "Vulnerability CVE-2024-39338 affects version 0.18.1-tuxcare.5 of axios, and is fixed in 0.18.1-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2024-39338"
      },
      "action_statement": "Vulnerability CVE-2024-39338 affects version 0.18.1-tuxcare.5 of axios, and is fixed in 0.18.1-tuxcare.6."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27152 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2025-27152"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58754 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2025-58754"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62718 does not affect version 0.18.1-tuxcare.5 of axios. axios 0.18.1 has no no_proxy support at all (added upstream in 38de2525, first released in 0.19.0), so the no_proxy hostname-normalization matching loop this CVE bypasses does not exist; the proxy is resolved solely via getProxyForUrl() with no hostname matching.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-62718"
      },
      "impact_statement": "axios 0.18.1 has no no_proxy support at all (added upstream in 38de2525, first released in 0.19.0), so the no_proxy hostname-normalization matching loop this CVE bypasses does not exist; the proxy is resolved solely via getProxyForUrl() with no hostname matching."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25639 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-25639"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39865 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 The target repository (axios 0.18.1-tuxcare.4) is not affected by CVE-2026-39865. This CVE describes an HTTP/2 session cleanup state corruption bug in the Http2Sessions class that was fixed in axios 1.13.2. The target version (0.18.1) predates the introduction of HTTP/2 support in axios, which was added in the 1.x series. The target's lib/adapters/http.js (302 lines) only supports HTTP/1.1 usin...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39865"
      },
      "impact_statement": "not_affected \u2014 The target repository (axios 0.18.1-tuxcare.4) is not affected by CVE-2026-39865. This CVE describes an HTTP/2 session cleanup state corruption bug in the Http2Sessions class that was fixed in axios 1.13.2. The target version (0.18.1) predates the introduction of HTTP/2 support in axios, which was added in the 1.x series. The target's lib/adapters/http.js (302 lines) only supports HTTP/1.1 usin..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40175 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-40175"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42033 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42033"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42034 does not affect version 0.18.1-tuxcare.5 of axios. axios 0.18.1 never reads config.maxBodyLength; lib/defaults.js defines only maxContentLength (a response-size limit), so there is no configurable request-body limit to bypass. Confirmed with a PoC against 0.18.1.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42034"
      },
      "impact_statement": "axios 0.18.1 never reads config.maxBodyLength; lib/defaults.js defines only maxContentLength (a response-size limit), so there is no configurable request-body limit to bypass. Confirmed with a PoC against 0.18.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42035 does not affect version 0.18.1-tuxcare.5 of axios. Version 0.18.1 (SHA 3256bcea) is NOT affected by CVE-2026-42035. The vulnerable code path does not exist in this version. The attack requires two components: (1) a duck-typed isFormData() function that can be fooled by prototype pollution, and (2) code in lib/adapters/http.js that calls data.getHeaders() and merges the result into request headers. Version 0.18.1 has NEITHER: isFormData() uses instanceof (cannot be spoofed), and http.js has no getHeaders() call. The vulnerable code was introduced AFTER this version in a major ES6 rewrite (302\u2192751 lines), then fixed by commit 854c54e0 authored by CloudLinux engineer Krystyna Tomaszewa. Type A2: INPUT (plain object with polluted properties) is received but no code path reaches GOAL (header injection) because transformRequest JSON-stringifies plain objects before they reach the http adapter.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42035"
      },
      "impact_statement": "Version 0.18.1 (SHA 3256bcea) is NOT affected by CVE-2026-42035. The vulnerable code path does not exist in this version. The attack requires two components: (1) a duck-typed isFormData() function that can be fooled by prototype pollution, and (2) code in lib/adapters/http.js that calls data.getHeaders() and merges the result into request headers. Version 0.18.1 has NEITHER: isFormData() uses instanceof (cannot be spoofed), and http.js has no getHeaders() call. The vulnerable code was introduced AFTER this version in a major ES6 rewrite (302\u2192751 lines), then fixed by commit 854c54e0 authored by CloudLinux engineer Krystyna Tomaszewa. Type A2: INPUT (plain object with polluted properties) is received but no code path reaches GOAL (header injection) because transformRequest JSON-stringifies plain objects before they reach the http adapter."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42036 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42036"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42038 does not affect version 0.18.1-tuxcare.5 of axios. The loopback-equivalence bug lives entirely inside the no_proxy matching loop of lib/adapters/http.js, and axios 0.18.1 has no no_proxy support (added upstream in 38de2525, first released in 0.19.0); neither the matching loop nor isLoopbackHost.js exists.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42038"
      },
      "impact_statement": "The loopback-equivalence bug lives entirely inside the no_proxy matching loop of lib/adapters/http.js, and axios 0.18.1 has no no_proxy support (added upstream in 38de2525, first released in 0.19.0); neither the matching loop nor isLoopbackHost.js exists."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42039 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42039"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42040 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 Version 0.18.1 is not affected by CVE-2026-42040. The vulnerable component `lib/helpers/AxiosURLSearchParams.js` does not exist in this version\u2014it was introduced in v1.0.0-alpha.1 (commit 934f390c), which postdates 0.18.1. The buildURL.js encode function that exists in 0.18.1 does not contain the reverse-encoding charMap entry ('\"%00\": \"\\x00\"') that causes the vulnerability. Testing confirms th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42040"
      },
      "impact_statement": "not_affected \u2014 Version 0.18.1 is not affected by CVE-2026-42040. The vulnerable component `lib/helpers/AxiosURLSearchParams.js` does not exist in this version\u2014it was introduced in v1.0.0-alpha.1 (commit 934f390c), which postdates 0.18.1. The buildURL.js encode function that exists in 0.18.1 does not contain the reverse-encoding charMap entry ('\"%00\": \"\\x00\"') that causes the vulnerability. Testing confirms th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42041 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 Axios v0.18.0 is NOT AFFECTED by CVE-2026-42041. The vulnerable code pattern (lib/core/mergeConfig.js with mergeDirectKeys function using the 'in' operator) was introduced in v0.22.0 (September 2021), more than 3 years after v0.18.0 was released (February 2018). Version 0.18.0 uses a completely different architecture: utils.merge() with forEach() that employs Object.prototype.hasOwnProperty che...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42041"
      },
      "impact_statement": "not_affected \u2014 Axios v0.18.0 is NOT AFFECTED by CVE-2026-42041. The vulnerable code pattern (lib/core/mergeConfig.js with mergeDirectKeys function using the 'in' operator) was introduced in v0.22.0 (September 2021), more than 3 years after v0.18.0 was released (February 2018). Version 0.18.0 uses a completely different architecture: utils.merge() with forEach() that employs Object.prototype.hasOwnProperty che..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42042 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 The target version (axios 0.18.1) is NOT AFFECTED by CVE-2026-42042. The vulnerability concerns the `withXSRFToken` configuration property introduced in later axios versions. Version 0.18.1 predates this feature and uses a completely different XSRF token mechanism based on the `withCredentials` property. Exhaustive searches confirm `withXSRFToken` does not exist anywhere in the codebase, and th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42042"
      },
      "impact_statement": "not_affected \u2014 The target version (axios 0.18.1) is NOT AFFECTED by CVE-2026-42042. The vulnerability concerns the `withXSRFToken` configuration property introduced in later axios versions. Version 0.18.1 predates this feature and uses a completely different XSRF token mechanism based on the `withCredentials` property. Exhaustive searches confirm `withXSRFToken` does not exist anywhere in the codebase, and th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42043 does not affect version 0.18.1-tuxcare.5 of axios. Target version 0.18.1 is not affected by CVE-2026-42043. The vulnerability describes an incomplete fix in lib/helpers/shouldBypassProxy.js (lines 1-3) where a hardcoded loopback address set recognizes only 127.0.0.1 instead of the full 127.0.0.0/8 subnet. Version 0.18.1 does not contain this file or any NO_PROXY handling logic. NO_PROXY support was first introduced in axios v0.19.0 (August 2018), and version 0.18.1 predates this feature entirely. The vulnerable code pattern is not present.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-42043"
      },
      "impact_statement": "Target version 0.18.1 is not affected by CVE-2026-42043. The vulnerability describes an incomplete fix in lib/helpers/shouldBypassProxy.js (lines 1-3) where a hardcoded loopback address set recognizes only 127.0.0.1 instead of the full 127.0.0.0/8 subnet. Version 0.18.1 does not contain this file or any NO_PROXY handling logic. NO_PROXY support was first introduced in axios v0.19.0 (August 2018), and version 0.18.1 predates this feature entirely. The vulnerable code pattern is not present."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44486 does not affect version 0.18.1-tuxcare.5 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44486 (Proxy-Authorization header leak on redirect). The fix was backported in commit 806a27b (also 3a086d9 in a backport branch), which implements the exact same defense as vendor commit afca61a070728e717203c2bc21e7b589b59b858b.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-44486"
      },
      "impact_statement": "already_fixed \u2014 The target repository already contains the fix for CVE-2026-44486 (Proxy-Authorization header leak on redirect). The fix was backported in commit 806a27b (also 3a086d9 in a backport branch), which implements the exact same defense as vendor commit afca61a070728e717203c2bc21e7b589b59b858b."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44487 does not affect version 0.18.1-tuxcare.5 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44487 (GHSA-j5f8-grm9-p9fc). The exact vendor commit afca61a070728e717203c2bc21e7b589b59b858b was backported in commit 806a27b as part of CVE-2024-28849 remediation on April 28, 2026. The defense mechanism strips stale Proxy-Authorization headers on redirect re-invocations, preventing credential leakage to unintended recipients.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-44487"
      },
      "impact_statement": "already_fixed \u2014 The target repository already contains the fix for CVE-2026-44487 (GHSA-j5f8-grm9-p9fc). The exact vendor commit afca61a070728e717203c2bc21e7b589b59b858b was backported in commit 806a27b as part of CVE-2024-28849 remediation on April 28, 2026. The defense mechanism strips stale Proxy-Authorization headers on redirect re-invocations, preventing credential leakage to unintended recipients."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44490 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44490"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44492 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 The target repository axios v0.18.1-tuxcare.2 does not implement NO_PROXY functionality at all. The vulnerability CVE-2026-44492 is specific to shouldBypassProxy.js (introduced in v1.15.0) which handles NO_PROXY hostname comparison. Since v0.18.1 predates this feature and has no hostname comparison or bypass logic, the vulnerability pattern cannot manifest.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-44492"
      },
      "impact_statement": "not_affected \u2014 The target repository axios v0.18.1-tuxcare.2 does not implement NO_PROXY functionality at all. The vulnerability CVE-2026-44492 is specific to shouldBypassProxy.js (introduced in v1.15.0) which handles NO_PROXY hostname comparison. Since v0.18.1 predates this feature and has no hostname comparison or bypass logic, the vulnerability pattern cannot manifest."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44496 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67316 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67319 is fixed in version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67319"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "GHSA-7q8q-rj6j-mhjq"
      },
      "action_statement": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.18.1-tuxcare.5 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.18.1-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.18.1-tuxcare.5 of axios.",
      "vulnerability": {
        "name": "GHSA-mmx7-hfxf-jppx"
      },
      "action_statement": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.18.1-tuxcare.5 of axios."
    }
  ]
}
