{
  "@id": "urn:uuid:7fc6bbfd-da90-4335-a659-05a701697712",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-01T17:31:29.124255+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57820 is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "CVE-2025-57820"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22774 does not affect version 4.3.3-tuxcare.5 of devalue. Version 4.3.3 is not vulnerable. Summary: The target repository (devalue version 4.3.3-tuxcare.2) is NOT vulnerable to CVE-2026-22774. The vulnerability affects versions 5.3.0 to 5.6.1, which include TypedArray and ArrayBuffer serialization/deserialization functionality. This functionality does not exist in version 4.x, therefore the vulnerable code patterns are not present. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22774"
      },
      "impact_statement": "Version 4.3.3 is not vulnerable. Summary: The target repository (devalue version 4.3.3-tuxcare.2) is NOT vulnerable to CVE-2026-22774. The vulnerability affects versions 5.3.0 to 5.6.1, which include TypedArray and ArrayBuffer serialization/deserialization functionality. This functionality does not exist in version 4.x, therefore the vulnerable code patterns are not present. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30226 does not affect version 4.3.3-tuxcare.5 of devalue. Version 4.3.3 is not vulnerable. Summary: The target repository (devalue v4.3.3-tuxcare.3) is NOT VULNERABLE to CVE-2026-30226. Although the vulnerable code pattern was originally introduced in this codebase, the target has been patched with backported security fixes from multiple advisories (GHSA-8qm3-746x-r74r, GHSA-mwv9-gp5h-frr4, and CVE-2025-57820). All prototype pollution attack vectors described in the CVE have been mitigated. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-30226"
      },
      "impact_statement": "Version 4.3.3 is not vulnerable. Summary: The target repository (devalue v4.3.3-tuxcare.3) is NOT VULNERABLE to CVE-2026-30226. Although the vulnerable code pattern was originally introduced in this codebase, the target has been patched with backported security fixes from multiple advisories (GHSA-8qm3-746x-r74r, GHSA-mwv9-gp5h-frr4, and CVE-2025-57820). All prototype pollution attack vectors described in the CVE have been mitigated. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42570 is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "CVE-2026-42570"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-81176 is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "CVE-2026-81176"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-33hq-fvwr-56pm is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-33hq-fvwr-56pm"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-4q55-j62x-fr9h affects version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-4q55-j62x-fr9h"
      },
      "action_statement": "Vulnerability GHSA-4q55-j62x-fr9h affects version 4.3.3-tuxcare.5 of devalue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8qm3-746x-r74r is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-8qm3-746x-r74r"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-30T10:20:49.796668+00:00",
      "status_notes": "Vulnerability GHSA-8qm3-746x-r74r-map-keys is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-8qm3-746x-r74r-map-keys"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-hx4r-w6wj-j8fg"
      },
      "action_statement": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 4.3.3-tuxcare.5 of devalue."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-mcm9-63f2-9j32"
      },
      "action_statement": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 4.3.3-tuxcare.5 of devalue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mwv9-gp5h-frr4 is fixed in version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-mwv9-gp5h-frr4"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-10-01T17:31:29.124255+00:00",
      "status_notes": "Vulnerability GHSA-r9w8-h9r3-54w4 does not affect version 4.3.3-tuxcare.5 of devalue. not_affected \u2014 Version 4.3.3-tuxcare.5 does not contain the vulnerable ArrayBuffer handling code. This version predates the addition of built-in ArrayBuffer support to devalue (added in upstream commit bbf86c2, Sept 2023, which was never merged into the 4.3.x maintenance branch). The parse() function has no \"ArrayBuffer\" case in its type switch statement, no base64.js encoding module exists, and comprehensive...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-r9w8-h9r3-54w4"
      },
      "impact_statement": "not_affected \u2014 Version 4.3.3-tuxcare.5 does not contain the vulnerable ArrayBuffer handling code. This version predates the addition of built-in ArrayBuffer support to devalue (added in upstream commit bbf86c2, Sept 2023, which was never merged into the 4.3.x maintenance branch). The parse() function has no \"ArrayBuffer\" case in its type switch statement, no base64.js encoding module exists, and comprehensive..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@4.3.3-tuxcare.5",
          "identifiers": {
            "purl": "pkg:npm/devalue@4.3.3-tuxcare.5"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-wf3x-273g-mvxv affects version 4.3.3-tuxcare.5 of devalue.",
      "vulnerability": {
        "name": "GHSA-wf3x-273g-mvxv"
      },
      "action_statement": "Vulnerability GHSA-wf3x-273g-mvxv affects version 4.3.3-tuxcare.5 of devalue."
    }
  ]
}
