{
  "@id": "urn:uuid:80470742-564b-4653-b210-74d2f1d5e79a",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-02T10:34:58.463788+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability CVE-2026-92708 is fixed in version 5.9.1-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "CVE-2026-92708"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability GHSA-4q55-j62x-fr9h does not affect version 5.9.1-tuxcare.1 of devalue. not_affected \u2014 The target repository (devalue v5.9.1, SHA ef97051b) is NOT AFFECTED by GHSA-4q55-j62x-fr9h. The vulnerability\u2014where malicious payloads could cause `parse` to create objects with `__proto__` as an own property\u2014has been fixed by the upstream vendor. Two explicit checks in src/parse.js (lines 157-159 for null-prototype objects, lines 258-260 for regular objects) throw errors when `__proto__` is e...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-4q55-j62x-fr9h"
      },
      "impact_statement": "not_affected \u2014 The target repository (devalue v5.9.1, SHA ef97051b) is NOT AFFECTED by GHSA-4q55-j62x-fr9h. The vulnerability\u2014where malicious payloads could cause `parse` to create objects with `__proto__` as an own property\u2014has been fixed by the upstream vendor. Two explicit checks in src/parse.js (lines 157-159 for null-prototype objects, lines 258-260 for regular objects) throw errors when `__proto__` is e..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability GHSA-hx4r-w6wj-j8fg is fixed in version 5.9.1-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-hx4r-w6wj-j8fg"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability GHSA-mcm9-63f2-9j32 does not affect version 5.9.1-tuxcare.1 of devalue. not_affected \u2014 The target version 5.9.1 is NOT affected by GHSA-mcm9-63f2-9j32. The vulnerability (sparse array amplification DoS) was fixed by upstream commit 819f1ac, which is present in version 5.9.1. The fix prevents the scenario where parsing a small serialized sparse array and passing it to uneval() could generate a massive output string by iterating millions of indices. Both stringify.js and uneval.js ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-mcm9-63f2-9j32"
      },
      "impact_statement": "not_affected \u2014 The target version 5.9.1 is NOT affected by GHSA-mcm9-63f2-9j32. The vulnerability (sparse array amplification DoS) was fixed by upstream commit 819f1ac, which is present in version 5.9.1. The fix prevents the scenario where parsing a small serialized sparse array and passing it to uneval() could generate a massive output string by iterating millions of indices. Both stringify.js and uneval.js ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability GHSA-r9w8-h9r3-54w4 is fixed in version 5.9.1-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-r9w8-h9r3-54w4"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.1-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-wf3x-273g-mvxv"
      },
      "action_statement": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.1-tuxcare.1 of devalue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:34:58.463788+00:00",
      "status_notes": "Vulnerability GHSA-x5rw-q4pp-hg5g is fixed in version 5.9.1-tuxcare.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-x5rw-q4pp-hg5g"
      }
    }
  ]
}
