{
  "@id": "urn:uuid:e0b61517-ed46-452f-92e7-4afce73f811f",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-2515 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2016-2515 concerns the 'hawk' HTTP authentication library, but the target repository is the 'ms' time conversion utility - a completely different project. No relationship exists between the two packages.",
      "vulnerability": {
        "name": "CVE-2016-2515"
      },
      "impact_statement": "false_positive \u2014 CVE-2016-2515 concerns the 'hawk' HTTP authentication library, but the target repository is the 'ms' time conversion utility - a completely different project. No relationship exists between the two packages."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-20162 is fixed in version 1.0.0-tuxcare.1 of ms.",
      "vulnerability": {
        "name": "CVE-2017-20162"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-3739 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2018-3739 is a wrong-project match. The advisory affects https-proxy-agent, but this repository is the ms package (a time conversion utility). The affected component's code is entirely absent from this repository.",
      "vulnerability": {
        "name": "CVE-2018-3739"
      },
      "impact_statement": "false_positive \u2014 CVE-2018-3739 is a wrong-project match. The advisory affects https-proxy-agent, but this repository is the ms package (a time conversion utility). The affected component's code is entirely absent from this repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-33623 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2021-33623 concerns the 'trim-newlines' npm package (ReDoS vulnerability in .end() method), but this repository is the 'ms' package (millisecond conversion utility). This is a wrong-project match - the two packages are completely unrelated with no dependency relationship.",
      "vulnerability": {
        "name": "CVE-2021-33623"
      },
      "impact_statement": "false_positive \u2014 CVE-2021-33623 concerns the 'trim-newlines' npm package (ReDoS vulnerability in .end() method), but this repository is the 'ms' package (millisecond conversion utility). This is a wrong-project match - the two packages are completely unrelated with no dependency relationship."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29167 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2022-29167 concerns the Hawk HTTP authentication library's Host header parsing (Hawk.utils.parseHost() ReDoS vulnerability). The target repository is the 'ms' (milliseconds) library - a time-string conversion utility unrelated to HTTP authentication or Host header parsing. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2022-29167"
      },
      "impact_statement": "false_positive \u2014 CVE-2022-29167 concerns the Hawk HTTP authentication library's Host header parsing (Hawk.utils.parseHost() ReDoS vulnerability). The target repository is the 'ms' (milliseconds) library - a time-string conversion utility unrelated to HTTP authentication or Host header parsing. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47178 is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 CVE-2024-47178 concerns 'basic-auth-connect' (an HTTP basic authentication middleware), but this repository is 'ms' (a time conversion utility). Wrong-project match - the affected component is completely absent from this repository.",
      "vulnerability": {
        "name": "CVE-2024-47178"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-47178 concerns 'basic-auth-connect' (an HTTP basic authentication middleware), but this repository is 'ms' (a time conversion utility). Wrong-project match - the affected component is completely absent from this repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/ms@1.0.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/ms@1.0.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pc5p-h8pf-mvwp is a false positive for ms 1.0.0-tuxcare.1. false_positive \u2014 GHSA-pc5p-h8pf-mvwp concerns https-proxy-agent, a TLS proxy agent package. The target repository is 'ms', a time conversion utility with no networking or proxy functionality. This is a wrong-project match.",
      "vulnerability": {
        "name": "GHSA-pc5p-h8pf-mvwp"
      },
      "impact_statement": "false_positive \u2014 GHSA-pc5p-h8pf-mvwp concerns https-proxy-agent, a TLS proxy agent package. The target repository is 'ms', a time conversion utility with no networking or proxy functionality. This is a wrong-project match."
    }
  ]
}
