{
  "@id": "urn:uuid:fcca905e-dead-4e27-b85d-384f20395911",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-2515 is a false positive for https-proxy-agent 1.0.0-tuxcare.1. false_positive \u2014 CVE-2016-2515 concerns the 'hawk' package (HTTP authentication library with ReDoS vulnerability), but the target repository is 'https-proxy-agent' (HTTP proxy connection library). The hawk package is completely absent from this repository - not as the project itself, not as vendored/bundled code, and not as a declared dependency. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2016-2515"
      },
      "impact_statement": "false_positive \u2014 CVE-2016-2515 concerns the 'hawk' package (HTTP authentication library with ReDoS vulnerability), but the target repository is 'https-proxy-agent' (HTTP proxy connection library). The hawk package is completely absent from this repository - not as the project itself, not as vendored/bundled code, and not as a declared dependency. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-20162 is a false positive for https-proxy-agent 1.0.0-tuxcare.1. false_positive \u2014 CVE-2017-20162 is a false positive for this repository. The advisory targets the 'vercel/ms' package (a time string parsing library), but this repository is 'https-proxy-agent' (an HTTP proxy implementation). The affected component's code (ms package's parse function with vulnerable regex) is completely absent from this repository - no vendored copy exists, and ms is not present in the dependen...",
      "vulnerability": {
        "name": "CVE-2017-20162"
      },
      "impact_statement": "false_positive \u2014 CVE-2017-20162 is a false positive for this repository. The advisory targets the 'vercel/ms' package (a time string parsing library), but this repository is 'https-proxy-agent' (an HTTP proxy implementation). The affected component's code (ms package's parse function with vulnerable regex) is completely absent from this repository - no vendored copy exists, and ms is not present in the dependen..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-3739 is fixed in version 1.0.0-tuxcare.1 of https-proxy-agent.",
      "vulnerability": {
        "name": "CVE-2018-3739"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33623 is a false positive for https-proxy-agent 1.0.0-tuxcare.1. false_positive \u2014 CVE-2021-33623 is a wrong-project match. The advisory concerns the trim-newlines package (a string utility for trimming newlines), but this repository is https-proxy-agent (an HTTP/HTTPS proxy implementation). Exhaustive containment search found no evidence of trim-newlines as the project itself, as a vendored/bundled copy, or as a declared/transitive dependency.",
      "vulnerability": {
        "name": "CVE-2021-33623"
      },
      "impact_statement": "false_positive \u2014 CVE-2021-33623 is a wrong-project match. The advisory concerns the trim-newlines package (a string utility for trimming newlines), but this repository is https-proxy-agent (an HTTP/HTTPS proxy implementation). Exhaustive containment search found no evidence of trim-newlines as the project itself, as a vendored/bundled copy, or as a declared/transitive dependency."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29167 is a false positive for https-proxy-agent 1.0.0-tuxcare.1. false_positive \u2014 CVE-2022-29167 targets the Hawk HTTP authentication library, but this repository is https-proxy-agent (an HTTP(s) proxy agent implementation). Product-Identity Check confirms this is a wrong-project match with no relationship between the two projects.",
      "vulnerability": {
        "name": "CVE-2022-29167"
      },
      "impact_statement": "false_positive \u2014 CVE-2022-29167 targets the Hawk HTTP authentication library, but this repository is https-proxy-agent (an HTTP(s) proxy agent implementation). Product-Identity Check confirms this is a wrong-project match with no relationship between the two projects."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47178 is a false positive for https-proxy-agent 1.0.0-tuxcare.1. false_positive \u2014 CVE-2024-47178 is a false positive for this repository. The CVE affects basic-auth-connect, a basic authentication middleware module, while this repository contains https-proxy-agent, an HTTP(S) proxy client library. These are completely different products with different purposes. The affected component (basic-auth-connect) is not present in this repository as the project itself, as a vendored ...",
      "vulnerability": {
        "name": "CVE-2024-47178"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-47178 is a false positive for this repository. The CVE affects basic-auth-connect, a basic authentication middleware module, while this repository contains https-proxy-agent, an HTTP(S) proxy client library. These are completely different products with different purposes. The affected component (basic-auth-connect) is not present in this repository as the project itself, as a vendored ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/https-proxy-agent@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pc5p-h8pf-mvwp is fixed in version 1.0.0-tuxcare.1 of https-proxy-agent.",
      "vulnerability": {
        "name": "GHSA-pc5p-h8pf-mvwp"
      }
    }
  ]
}
