{
  "@id": "urn:uuid:3123d827-d655-473a-b54d-0b16f9aa1167",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 5,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T16:36:57.583767+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27152 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2025-27152"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-58754 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2025-58754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-62718 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2025-62718"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T15:22:01.103634+00:00",
      "status_notes": "Vulnerability CVE-2026-101902 affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-101902"
      },
      "action_statement": "Vulnerability CVE-2026-101902 affects version 1.7.5-tuxcare.4 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101904 affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-101904"
      },
      "action_statement": "Vulnerability CVE-2026-101904 affects version 1.7.5-tuxcare.4 of axios."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T16:36:57.583767+00:00",
      "status_notes": "Vulnerability CVE-2026-101908 does not affect version 1.7.5-tuxcare.4 of axios. not_affected \u2014 Version 1.7.5 is not affected by CVE-2026-101908. The vulnerability requires passing fetchOptions as the second argument to fetch(), creating a path for prototype-polluted properties to override the Request's headers. This pattern was introduced in commit 0f50af8e (June 2025), first appearing in v1.10.0. Version 1.7.5 predates this change and calls fetch(request) with only one argument, prevent...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-101908"
      },
      "impact_statement": "not_affected \u2014 Version 1.7.5 is not affected by CVE-2026-101908. The vulnerability requires passing fetchOptions as the second argument to fetch(), creating a path for prototype-polluted properties to override the Request's headers. This pattern was introduced in commit 0f50af8e (June 2025), first appearing in v1.10.0. Version 1.7.5 predates this change and calls fetch(request) with only one argument, prevent..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25639 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-25639"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40175 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-40175"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42033 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42033"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42034 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42034"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42035 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42036 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42036"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42037 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42037"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42038 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42038"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42039 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42039"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42040 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42040"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42041 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42041"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42042 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42043 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42044 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42044"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42264 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-42264"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44486 affects version 1.7.5-tuxcare.4 of axios, and is fixed in 1.7.5-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-44486"
      },
      "action_statement": "Vulnerability CVE-2026-44486 affects version 1.7.5-tuxcare.4 of axios, and is fixed in 1.7.5-tuxcare.5."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44487 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44487"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44488 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44488"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44490 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44490"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44492 affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44492"
      },
      "action_statement": "Vulnerability CVE-2026-44492 affects version 1.7.5-tuxcare.4 of axios."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44494 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44494"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44495 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44496 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-44496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67312 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67312"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67313 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67313"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67316 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67317 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67317"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-30T08:14:17.776706+00:00",
      "status_notes": "Vulnerability CVE-2026-67319 is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "CVE-2026-67319"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "GHSA-42h9-826w-cgv3"
      },
      "action_statement": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.7.5-tuxcare.4 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "GHSA-7q8q-rj6j-mhjq"
      },
      "action_statement": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.7.5-tuxcare.4 of axios."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jqh4-m9w3-8hp9 affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "GHSA-jqh4-m9w3-8hp9"
      },
      "action_statement": "Vulnerability GHSA-jqh4-m9w3-8hp9 affects version 1.7.5-tuxcare.4 of axios."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "GHSA-mmx7-hfxf-jppx"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/axios@1.7.5-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/axios@1.7.5-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.7.5-tuxcare.4 of axios.",
      "vulnerability": {
        "name": "GHSA-pmv8-rq9r-6j72"
      },
      "action_statement": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.7.5-tuxcare.4 of axios."
    }
  ]
}
