{
  "@id": "urn:uuid:af9fa48a-dbab-498c-8ec2-362046a388f1",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-01T17:36:03.503905+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:24:00.092325+00:00",
      "status_notes": "Vulnerability CVE-2025-57820 is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "CVE-2025-57820"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:24:00.092325+00:00",
      "status_notes": "Vulnerability CVE-2026-22774 does not affect version 4.3.0-tuxcare.2 of devalue. Target version 4.3.0 is not affected by CVE-2026-22774. The vulnerability exists in TypedArray hydration code that validates ArrayBuffer inputs, but TypedArray support was not introduced until version 5.1.0. Version 4.3.0 predates this feature entirely. When typed array serialized data is provided to this version, the parser throws \"Unknown type Int8Array\" error rather than attempting hydration, preventing the DoS condition described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22774"
      },
      "impact_statement": "Target version 4.3.0 is not affected by CVE-2026-22774. The vulnerability exists in TypedArray hydration code that validates ArrayBuffer inputs, but TypedArray support was not introduced until version 5.1.0. Version 4.3.0 predates this feature entirely. When typed array serialized data is provided to this version, the parser throws \"Unknown type Int8Array\" error rather than attempting hydration, preventing the DoS condition described in the CVE."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:24:00.092325+00:00",
      "status_notes": "Vulnerability CVE-2026-30226 is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "CVE-2026-30226"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:25:00.212673+00:00",
      "status_notes": "Vulnerability CVE-2026-42570 is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "CVE-2026-42570"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:25:00.212673+00:00",
      "status_notes": "Vulnerability CVE-2026-81176 is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "CVE-2026-81176"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:24:00.092325+00:00",
      "status_notes": "Vulnerability GHSA-33hq-fvwr-56pm is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-33hq-fvwr-56pm"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-4q55-j62x-fr9h affects version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-4q55-j62x-fr9h"
      },
      "action_statement": "Vulnerability GHSA-4q55-j62x-fr9h affects version 4.3.0-tuxcare.2 of devalue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:24:00.092325+00:00",
      "status_notes": "Vulnerability GHSA-8qm3-746x-r74r is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-8qm3-746x-r74r"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-hx4r-w6wj-j8fg"
      },
      "action_statement": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 4.3.0-tuxcare.2 of devalue."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-mcm9-63f2-9j32"
      },
      "action_statement": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 4.3.0-tuxcare.2 of devalue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-28T14:24:00.092325+00:00",
      "status_notes": "Vulnerability GHSA-mwv9-gp5h-frr4 is fixed in version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-mwv9-gp5h-frr4"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-10-01T17:36:03.503905+00:00",
      "status_notes": "Vulnerability GHSA-r9w8-h9r3-54w4 does not affect version 4.3.0-tuxcare.2 of devalue. not_affected \u2014 Version 4.3.0 is not affected by GHSA-r9w8-h9r3-54w4. The vulnerability requires built-in ArrayBuffer handling code that does not exist in this version. Built-in ArrayBuffer support was only added in v4.3.3+ (commit bbf86c2df54). While users can provide custom ArrayBuffer revivers, those are application-level code outside the library's scope. The library itself never creates ArrayBuffer objects...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-r9w8-h9r3-54w4"
      },
      "impact_statement": "not_affected \u2014 Version 4.3.0 is not affected by GHSA-r9w8-h9r3-54w4. The vulnerability requires built-in ArrayBuffer handling code that does not exist in this version. Built-in ArrayBuffer support was only added in v4.3.3+ (commit bbf86c2df54). While users can provide custom ArrayBuffer revivers, those are application-level code outside the library's scope. The library itself never creates ArrayBuffer objects..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-wf3x-273g-mvxv affects version 4.3.0-tuxcare.2 of devalue.",
      "vulnerability": {
        "name": "GHSA-wf3x-273g-mvxv"
      },
      "action_statement": "Vulnerability GHSA-wf3x-273g-mvxv affects version 4.3.0-tuxcare.2 of devalue."
    }
  ]
}
