{
  "@id": "urn:uuid:345dc2f4-a2ad-4809-9ddf-eed7a5354418",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-02T18:20:03.376685+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T18:20:03.376685+00:00",
      "status_notes": "Vulnerability CVE-2026-92708 affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-92708"
      },
      "action_statement": "Vulnerability CVE-2026-92708 affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.3."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T20:58:06.023433+00:00",
      "status_notes": "Vulnerability GHSA-4q55-j62x-fr9h is fixed in version 5.9.0-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-4q55-j62x-fr9h"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T20:58:06.023433+00:00",
      "status_notes": "Vulnerability GHSA-hx4r-w6wj-j8fg does not affect version 5.9.0-tuxcare.1 of devalue. not_affected \u2014 The target repository (devalue v5.9.0) is not affected by GHSA-hx4r-w6wj-j8fg (sparse array DoS in uneval). The vulnerability was fixed in upstream commit 819f1ac7 (2026-02-18) by Elliott Johnson, which added Object.assign optimization to avoid O(n) iteration through sparse array indices. This fix is already present in the shipped v5.9.0 release. The vulnerable pattern (for loop iterating from ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-hx4r-w6wj-j8fg"
      },
      "impact_statement": "not_affected \u2014 The target repository (devalue v5.9.0) is not affected by GHSA-hx4r-w6wj-j8fg (sparse array DoS in uneval). The vulnerability was fixed in upstream commit 819f1ac7 (2026-02-18) by Elliott Johnson, which added Object.assign optimization to avoid O(n) iteration through sparse array indices. This fix is already present in the shipped v5.9.0 release. The vulnerable pattern (for loop iterating from ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T11:02:17.236778+00:00",
      "status_notes": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.2.",
      "vulnerability": {
        "name": "GHSA-mcm9-63f2-9j32"
      },
      "action_statement": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T18:20:03.376685+00:00",
      "status_notes": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.3.",
      "vulnerability": {
        "name": "GHSA-r9w8-h9r3-54w4"
      },
      "action_statement": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T20:58:06.023433+00:00",
      "status_notes": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.0-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-wf3x-273g-mvxv"
      },
      "action_statement": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.0-tuxcare.1 of devalue."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T18:20:03.376685+00:00",
      "status_notes": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.3.",
      "vulnerability": {
        "name": "GHSA-x5rw-q4pp-hg5g"
      },
      "action_statement": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.0-tuxcare.1 of devalue, and is fixed in 5.9.0-tuxcare.3."
    }
  ]
}
