{
  "@id": "urn:uuid:94c57ffa-e165-4835-a6c3-3d419b459d4b",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T08:14:17.776706+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45857 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2023-45857"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-39338 does not affect version 0.24.0-tuxcare.2 of axios. Target version 0.24.0 is NOT affected by CVE-2024-39338. The vulnerability exists in axios 1.7.2+ which uses the WHATWG URL constructor (new URL()) that resolves protocol-relative URLs. The target uses the legacy Node.js url.parse() API which does not treat '//attacker.com' as protocol-relative, breaking the SSRF attack chain. Testing confirms url.parse('//attacker.com:8888') returns hostname=null (treated as pathname), causing HTTP requests to default to localhost instead of the attacker's server.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-39338"
      },
      "impact_statement": "Target version 0.24.0 is NOT affected by CVE-2024-39338. The vulnerability exists in axios 1.7.2+ which uses the WHATWG URL constructor (new URL()) that resolves protocol-relative URLs. The target uses the legacy Node.js url.parse() API which does not treat '//attacker.com' as protocol-relative, breaking the SSRF attack chain. Testing confirms url.parse('//attacker.com:8888') returns hostname=null (treated as pathname), causing HTTP requests to default to localhost instead of the attacker's server."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27152 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2025-27152"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62718 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2025-62718"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25639 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-25639"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40175 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-40175"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42033 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42034 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42035 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42036 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42036"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42038 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42038"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42039 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42039"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42040 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42041 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42041"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42042 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42043 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42043"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44486 affects version 0.24.0-tuxcare.2 of axios, and is fixed in 0.24.0-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-44486"
      },
      "action_statement": "Vulnerability CVE-2026-44486 affects version 0.24.0-tuxcare.2 of axios, and is fixed in 0.24.0-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44487 affects version 0.24.0-tuxcare.2 of axios, and is fixed in 0.24.0-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-44487"
      },
      "action_statement": "Vulnerability CVE-2026-44487 affects version 0.24.0-tuxcare.2 of axios, and is fixed in 0.24.0-tuxcare.4."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44490 affects version 0.24.0-tuxcare.2 of axios, and is fixed in 0.24.0-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-44490"
      },
      "action_statement": "Vulnerability CVE-2026-44490 affects version 0.24.0-tuxcare.2 of axios, and is fixed in 0.24.0-tuxcare.3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44492 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44492"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44495 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44496 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67316 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67319 is fixed in version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67319"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "GHSA-7q8q-rj6j-mhjq"
      },
      "action_statement": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.24.0-tuxcare.2 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.24.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/axios@0.24.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.24.0-tuxcare.2 of axios.",
      "vulnerability": {
        "name": "GHSA-mmx7-hfxf-jppx"
      },
      "action_statement": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.24.0-tuxcare.2 of axios."
    }
  ]
}
