{
  "@id": "urn:uuid:8b84bf29-f9dc-47d0-9af9-181c79a75219",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-02T10:21:52.156694+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:21:52.156694+00:00",
      "status_notes": "Vulnerability CVE-2026-92708 affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-92708"
      },
      "action_statement": "Vulnerability CVE-2026-92708 affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-01T17:03:47.558536+00:00",
      "status_notes": "Vulnerability GHSA-4q55-j62x-fr9h does not affect version 5.9.1 of devalue. not_affected \u2014 The target repository (devalue v5.9.1, SHA ef97051b) is NOT AFFECTED by GHSA-4q55-j62x-fr9h. The vulnerability\u2014where malicious payloads could cause `parse` to create objects with `__proto__` as an own property\u2014has been fixed by the upstream vendor. Two explicit checks in src/parse.js (lines 157-159 for null-prototype objects, lines 258-260 for regular objects) throw errors when `__proto__` is e...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-4q55-j62x-fr9h"
      },
      "impact_statement": "not_affected \u2014 The target repository (devalue v5.9.1, SHA ef97051b) is NOT AFFECTED by GHSA-4q55-j62x-fr9h. The vulnerability\u2014where malicious payloads could cause `parse` to create objects with `__proto__` as an own property\u2014has been fixed by the upstream vendor. Two explicit checks in src/parse.js (lines 157-159 for null-prototype objects, lines 258-260 for regular objects) throw errors when `__proto__` is e..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:21:52.156694+00:00",
      "status_notes": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-hx4r-w6wj-j8fg"
      },
      "action_statement": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-01T17:24:35.076027+00:00",
      "status_notes": "Vulnerability GHSA-mcm9-63f2-9j32 does not affect version 5.9.1 of devalue. not_affected \u2014 The target version 5.9.1 is NOT affected by GHSA-mcm9-63f2-9j32. The vulnerability (sparse array amplification DoS) was fixed by upstream commit 819f1ac, which is present in version 5.9.1. The fix prevents the scenario where parsing a small serialized sparse array and passing it to uneval() could generate a massive output string by iterating millions of indices. Both stringify.js and uneval.js ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-mcm9-63f2-9j32"
      },
      "impact_statement": "not_affected \u2014 The target version 5.9.1 is NOT affected by GHSA-mcm9-63f2-9j32. The vulnerability (sparse array amplification DoS) was fixed by upstream commit 819f1ac, which is present in version 5.9.1. The fix prevents the scenario where parsing a small serialized sparse array and passing it to uneval() could generate a massive output string by iterating millions of indices. Both stringify.js and uneval.js ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:21:52.156694+00:00",
      "status_notes": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-r9w8-h9r3-54w4"
      },
      "action_statement": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-01T15:25:17.861384+00:00",
      "status_notes": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.1 of devalue.",
      "vulnerability": {
        "name": "GHSA-wf3x-273g-mvxv"
      },
      "action_statement": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.1 of devalue."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.1",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.1"
          }
        }
      ],
      "timestamp": "2026-10-02T10:21:52.156694+00:00",
      "status_notes": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-x5rw-q4pp-hg5g"
      },
      "action_statement": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
    }
  ]
}
