{
  "@id": "urn:uuid:19c5f5fc-a583-4ce7-abd8-59ce8420a1b9",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-01T07:10:28.037150+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45857 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2023-45857"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-10-01T07:10:28.037150+00:00",
      "status_notes": "Vulnerability CVE-2024-39338 does not affect version 0.26.1-tuxcare.3 of axios. Version 0.26.1 is NOT affected by CVE-2024-39338. The vulnerability requires WHATWG URL constructor parsing (introduced in axios 1.x), which resolves protocol-relative URLs like `//host:port` by extracting hostname and port. Version 0.26.1 uses legacy Node.js `url.parse()`, which treats `//host:port` as a pathname string, not a URL. When `url.parse('//localhost:4667')` is called, it returns hostname=null and port=null (defaulting to localhost:80), preventing the SSRF attack. The attack chain from INPUT (protocol-relative URL) to GOAL (request to attacker-controlled host) is broken by the architectural difference in URL parsing.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-39338"
      },
      "impact_statement": "Version 0.26.1 is NOT affected by CVE-2024-39338. The vulnerability requires WHATWG URL constructor parsing (introduced in axios 1.x), which resolves protocol-relative URLs like `//host:port` by extracting hostname and port. Version 0.26.1 uses legacy Node.js `url.parse()`, which treats `//host:port` as a pathname string, not a URL. When `url.parse('//localhost:4667')` is called, it returns hostname=null and port=null (defaulting to localhost:80), preventing the SSRF attack. The attack chain from INPUT (protocol-relative URL) to GOAL (request to attacker-controlled host) is broken by the architectural difference in URL parsing."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27152 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2025-27152"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62718 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2025-62718"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25639 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-25639"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40175 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-40175"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42033 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42034 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42035 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42036 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42036"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42038 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42038"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42039 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42039"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42040 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42041 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42041"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42042 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42043 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42043"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44486 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.4.",
      "vulnerability": {
        "name": "CVE-2026-44486"
      },
      "action_statement": "Vulnerability CVE-2026-44486 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.4."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44487 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44487"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44490 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44490"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44492 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-44492"
      },
      "action_statement": "Vulnerability CVE-2026-44492 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44495 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-44495"
      },
      "action_statement": "Vulnerability CVE-2026-44495 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44496 is fixed in version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44496"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67316 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-67316"
      },
      "action_statement": "Vulnerability CVE-2026-67316 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67319 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-67319"
      },
      "action_statement": "Vulnerability CVE-2026-67319 affects version 0.26.1-tuxcare.3 of axios, and is fixed in 0.26.1-tuxcare.5."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-7q8q-rj6j-mhjq"
      },
      "action_statement": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.26.1-tuxcare.3 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@0.26.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/axios@0.26.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.26.1-tuxcare.3 of axios.",
      "vulnerability": {
        "name": "GHSA-mmx7-hfxf-jppx"
      },
      "action_statement": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.26.1-tuxcare.3 of axios."
    }
  ]
}
