{
  "@id": "urn:uuid:f6699011-667e-4a0a-9ced-4cb57df111ef",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-01T20:55:44.739744+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T20:55:44.739744+00:00",
      "status_notes": "Vulnerability CVE-2026-92708 affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-92708"
      },
      "action_statement": "Vulnerability CVE-2026-92708 affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T16:59:00.265816+00:00",
      "status_notes": "Vulnerability GHSA-4q55-j62x-fr9h does not affect version 5.9.2 of devalue. not_affected \u2014 The target devalue 5.9.2 is NOT affected by GHSA-4q55-j62x-fr9h. The vulnerability (parse creating objects with __proto__ own properties) was fixed by upstream vendor in version 5.6.4 (commit 87c1f3c, March 2026). The fix adds explicit checks that throw errors when __proto__ appears as a property key during parsing, preventing the creation of objects with __proto__ as an enumerable own property...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-4q55-j62x-fr9h"
      },
      "impact_statement": "not_affected \u2014 The target devalue 5.9.2 is NOT affected by GHSA-4q55-j62x-fr9h. The vulnerability (parse creating objects with __proto__ own properties) was fixed by upstream vendor in version 5.6.4 (commit 87c1f3c, March 2026). The fix adds explicit checks that throw errors when __proto__ appears as a property key during parsing, preventing the creation of objects with __proto__ as an enumerable own property..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T20:55:44.739744+00:00",
      "status_notes": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-hx4r-w6wj-j8fg"
      },
      "action_statement": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T17:24:35.076027+00:00",
      "status_notes": "Vulnerability GHSA-mcm9-63f2-9j32 does not affect version 5.9.2 of devalue. not_affected \u2014 The target repository (devalue v5.9.2) is NOT AFFECTED by GHSA-mcm9-63f2-9j32. The vulnerability described \u2014 data amplification where parsed sparse arrays passed to uneval generate extremely large serialized strings \u2014 was fixed in upstream commit 819f1ac (Feb 2026) by Elliott Johnson. The fix implements a cost-based heuristic to avoid iterating through sparse array holes: when hole_cost > spars...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-mcm9-63f2-9j32"
      },
      "impact_statement": "not_affected \u2014 The target repository (devalue v5.9.2) is NOT AFFECTED by GHSA-mcm9-63f2-9j32. The vulnerability described \u2014 data amplification where parsed sparse arrays passed to uneval generate extremely large serialized strings \u2014 was fixed in upstream commit 819f1ac (Feb 2026) by Elliott Johnson. The fix implements a cost-based heuristic to avoid iterating through sparse array holes: when hole_cost > spars..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T20:55:44.739744+00:00",
      "status_notes": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-r9w8-h9r3-54w4"
      },
      "action_statement": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T20:55:44.739744+00:00",
      "status_notes": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-wf3x-273g-mvxv"
      },
      "action_statement": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/devalue@5.9.2",
          "identifiers": {
            "purl": "pkg:npm/devalue@5.9.2"
          }
        }
      ],
      "timestamp": "2026-10-01T20:55:44.739744+00:00",
      "status_notes": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-x5rw-q4pp-hg5g"
      },
      "action_statement": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.2 of devalue, and is fixed in 5.9.2-tuxcare.1."
    }
  ]
}
