{
  "@id": "urn:uuid:d1c7ac00-4611-459f-b495-9754f3059883",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-1000048 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2017-1000048 affects the 'qs' (query string parser) package, but this repository is 'on-headers' version 1.0.2, a completely different package for HTTP response header manipulation. The affected component (qs.parse and query string parsing functionality) is absent from the entire repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2017-1000048"
      },
      "impact_statement": "false_positive \u2014 CVE-2017-1000048 affects the 'qs' (query string parser) package, but this repository is 'on-headers' version 1.0.2, a completely different package for HTTP response header manipulation. The affected component (qs.parse and query string parsing functionality) is absent from the entire repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-16487 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2018-16487 concerns lodash prototype pollution, but this repository is on-headers (a Node.js HTTP header utility). Lodash is not present as the project itself, as vendored code, or as a dependency. This is a wrong-project advisory match.",
      "vulnerability": {
        "name": "CVE-2018-16487"
      },
      "impact_statement": "false_positive \u2014 CVE-2018-16487 concerns lodash prototype pollution, but this repository is on-headers (a Node.js HTTP header utility). Lodash is not present as the project itself, as vendored code, or as a dependency. This is a wrong-project advisory match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-3721 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2018-3721 concerns lodash prototype pollution, but target repository is on-headers (HTTP header listener library). Wrong-project match: lodash code is entirely absent from this repository.",
      "vulnerability": {
        "name": "CVE-2018-3721"
      },
      "impact_statement": "false_positive \u2014 CVE-2018-3721 concerns lodash prototype pollution, but target repository is on-headers (HTTP header listener library). Wrong-project match: lodash code is entirely absent from this repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-1010266 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2019-1010266 concerns lodash's Date handler ReDoS vulnerability. The target repository is on-headers (version 1.0.2), a completely different Node.js package for HTTP header listener management. Exhaustive containment search found no lodash code, vendored copy, or dependency relationship. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2019-1010266"
      },
      "impact_statement": "false_positive \u2014 CVE-2019-1010266 concerns lodash's Date handler ReDoS vulnerability. The target repository is on-headers (version 1.0.2), a completely different Node.js package for HTTP header listener management. Exhaustive containment search found no lodash code, vendored copy, or dependency relationship. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-10744 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2019-10744 concerns lodash's defaultsDeep prototype pollution vulnerability, but the target repository is on-headers v1.0.2, a completely different Node.js library for HTTP header event handling. The CVE was matched to the wrong project.",
      "vulnerability": {
        "name": "CVE-2019-10744"
      },
      "impact_statement": "false_positive \u2014 CVE-2019-10744 concerns lodash's defaultsDeep prototype pollution vulnerability, but the target repository is on-headers v1.0.2, a completely different Node.js library for HTTP header event handling. The CVE was matched to the wrong project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-28500 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2020-28500 concerns lodash (a JavaScript utility library) versions prior to 4.17.21, specifically ReDoS vulnerabilities in toNumber, trim, and trimEnd functions. The target repository is on-headers v1.0.2, a completely different Node.js package that provides HTTP header event handling. No relationship exists between the two projects - lodash is not vendored, not a dependency, and the vulner...",
      "vulnerability": {
        "name": "CVE-2020-28500"
      },
      "impact_statement": "false_positive \u2014 CVE-2020-28500 concerns lodash (a JavaScript utility library) versions prior to 4.17.21, specifically ReDoS vulnerabilities in toNumber, trim, and trimEnd functions. The target repository is on-headers v1.0.2, a completely different Node.js package that provides HTTP header event handling. No relationship exists between the two projects - lodash is not vendored, not a dependency, and the vulner..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-23337 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2021-23337 is a wrong-project match. The advisory concerns the 'lodash' library's template function command injection vulnerability, but the target repository is 'on-headers' (version 1.0.2), a completely different Node.js package for HTTP header manipulation. Lodash is not present in the repository as the project itself, as vendored code, or as a dependency.",
      "vulnerability": {
        "name": "CVE-2021-23337"
      },
      "impact_statement": "false_positive \u2014 CVE-2021-23337 is a wrong-project match. The advisory concerns the 'lodash' library's template function command injection vulnerability, but the target repository is 'on-headers' (version 1.0.2), a completely different Node.js package for HTTP header manipulation. Lodash is not present in the repository as the project itself, as vendored code, or as a dependency."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24999 is a false positive for on-headers 1.0.2-tuxcare.1. false_positive \u2014 CVE-2022-24999 concerns the 'qs' query string parser library, but the target repository is 'on-headers', an HTTP response header listener utility. This is a wrong-project match - the affected component is completely absent from this repository.",
      "vulnerability": {
        "name": "CVE-2022-24999"
      },
      "impact_statement": "false_positive \u2014 CVE-2022-24999 concerns the 'qs' query string parser library, but the target repository is 'on-headers', an HTTP response header listener utility. This is a wrong-project match - the affected component is completely absent from this repository."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/on-headers@1.0.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/on-headers@1.0.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-7339 is fixed in version 1.0.2-tuxcare.1 of on-headers.",
      "vulnerability": {
        "name": "CVE-2025-7339"
      }
    }
  ]
}
