{
  "@id": "urn:uuid:5866e838-8fda-43fc-a3b9-8f9d1394c587",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-03T10:13:00.652366+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/js-yaml@4.3.2",
          "identifiers": {
            "purl": "pkg:npm/js-yaml@4.3.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59868 does not affect version 4.3.2 of js-yaml. not_affected \u2014 CVE-2026-59868 addresses quadratic CPU time consumption when parsing YAML with chained merge keys. The target repository (js-yaml 4.3.2) already contains the complete fix that addresses this vulnerability. The defense mechanism (`maxTotalMergeKeys` with default limit of 10,000) was backported from v5 by upstream maintainer Vitaly Puzrin in commit d90b661. The fix is functionally equivalent to t...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59868"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-59868 addresses quadratic CPU time consumption when parsing YAML with chained merge keys. The target repository (js-yaml 4.3.2) already contains the complete fix that addresses this vulnerability. The defense mechanism (`maxTotalMergeKeys` with default limit of 10,000) was backported from v5 by upstream maintainer Vitaly Puzrin in commit d90b661. The fix is functionally equivalent to t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/js-yaml@4.3.2",
          "identifiers": {
            "purl": "pkg:npm/js-yaml@4.3.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59870 does not affect version 4.3.2 of js-yaml. not_affected \u2014 Target version 4.3.2 is NOT AFFECTED. The O(n\u00b2) algorithmic complexity vulnerability (CVE-2026-59870) in js-yaml's !!omap duplicate detection was present in version 4.3.0 (used array.indexOf for O(n) per-insertion scan) but was fixed by upstream vendor commit c3cc4b0 (2026-07-31) which replaced it with O(1) hash-based lookup. The fix is present in HEAD (ad6f1d0, version 4.3.2). This is an upstr...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59870"
      },
      "impact_statement": "not_affected \u2014 Target version 4.3.2 is NOT AFFECTED. The O(n\u00b2) algorithmic complexity vulnerability (CVE-2026-59870) in js-yaml's !!omap duplicate detection was present in version 4.3.0 (used array.indexOf for O(n) per-insertion scan) but was fixed by upstream vendor commit c3cc4b0 (2026-07-31) which replaced it with O(1) hash-based lookup. The fix is present in HEAD (ad6f1d0, version 4.3.2). This is an upstr..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/js-yaml@4.3.2",
          "identifiers": {
            "purl": "pkg:npm/js-yaml@4.3.2"
          }
        }
      ],
      "timestamp": "2026-10-03T10:13:00.652366+00:00",
      "status_notes": "Vulnerability CVE-2026-73643 does not affect version 4.3.2 of js-yaml. Version 4.3.2 is NOT affected by CVE-2026-73643. The vulnerability was introduced in version 5.0.0's TypeScript rewrite with a new event-based parser architecture. The vulnerable pattern (restoreState() + double-parseNode() causing exponential reparsing of nested flow sequence keys) does not exist in version 4.3.2's JavaScript implementation. Testing confirms: pathological payloads that would cause exponential time in 5.0.0-5.2.2 complete in 4-6ms in version 4.3.2, with no exponential behavior even at 60 levels of nesting.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-73643"
      },
      "impact_statement": "Version 4.3.2 is NOT affected by CVE-2026-73643. The vulnerability was introduced in version 5.0.0's TypeScript rewrite with a new event-based parser architecture. The vulnerable pattern (restoreState() + double-parseNode() causing exponential reparsing of nested flow sequence keys) does not exist in version 4.3.2's JavaScript implementation. Testing confirms: pathological payloads that would cause exponential time in 5.0.0-5.2.2 complete in 4-6ms in version 4.3.2, with no exponential behavior even at 60 levels of nesting."
    }
  ]
}
