{
  "@id": "urn:uuid:83fd6ee2-a3e1-4a39-a78c-5b862a451930",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/protobufjs@3.8.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54270 does not affect version 3.8.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 3.8.2 is not affected by CVE-2026-54270. The vulnerability requires the unknown field preservation feature introduced in protobufjs 8.2.0, which does not exist in this version. Version 3.8.2 always discards unknown fields during decode by advancing the buffer position without retaining the data.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54270"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.2 is not affected by CVE-2026-54270. The vulnerability requires the unknown field preservation feature introduced in protobufjs 8.2.0, which does not exist in this version. Version 3.8.2 always discards unknown fields during decode by advancing the buffer position without retaining the data."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/protobufjs@3.8.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59876 does not affect version 3.8.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 3.8.2 does not contain the Text Format extension or map field support. The vulnerability requires parsing protobuf text format input with string-keyed map fields using ext/textformat.js, which does not exist in this version. This is a proto2-only implementation from 2014 that predates the affected features.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59876"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.2 does not contain the Text Format extension or map field support. The vulnerability requires parsing protobuf text format input with string-keyed map fields using ext/textformat.js, which does not exist in this version. This is a proto2-only implementation from 2014 that predates the affected features."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/protobufjs@3.8.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59877 does not affect version 3.8.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 3.8.2 is not affected by CVE-2026-59877. The vulnerability requires a 'while (token !== \"=\")' loop in option parsing that can run indefinitely when EOF is reached. Version 3.8.2 uses a fundamentally different architecture with sequential token consumption and immediate validation, making the infinite loop pattern impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59877"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.2 is not affected by CVE-2026-59877. The vulnerability requires a 'while (token !== \"=\")' loop in option parsing that can run indefinitely when EOF is reached. Version 3.8.2 uses a fundamentally different architecture with sequential token consumption and immediate validation, making the infinite loop pattern impossible."
    }
  ]
}
