{
  "@id": "urn:uuid:f1d748c8-a182-4bb6-b0b1-80d83e2f4379",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-10064 is fixed in version 0.5.1-tuxcare.1 of qs.",
      "vulnerability": {
        "name": "CVE-2014-10064"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-7191 is fixed in version 0.5.1-tuxcare.1 of qs.",
      "vulnerability": {
        "name": "CVE-2014-7191"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-1000048 is fixed in version 0.5.1-tuxcare.1 of qs.",
      "vulnerability": {
        "name": "CVE-2017-1000048"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24999 is fixed in version 0.5.1-tuxcare.1 of qs.",
      "vulnerability": {
        "name": "CVE-2022-24999"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15284 is fixed in version 0.5.1-tuxcare.1 of qs.",
      "vulnerability": {
        "name": "CVE-2025-15284"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2391 does not affect version 0.5.1-tuxcare.1 of qs. not_affected \u2014 Version 0.5.1 does not support comma-parsing of query string values. The vulnerability requires the 'comma: true' option, which was introduced in qs v6.7.0 (September 2018), approximately 6 years after this version. The comma-parsing feature and the vulnerable code path (lib/parse.js with comma-split logic) do not exist in this version's architecture.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2391"
      },
      "impact_statement": "not_affected \u2014 Version 0.5.1 does not support comma-parsing of query string values. The vulnerability requires the 'comma: true' option, which was introduced in qs v6.7.0 (September 2018), approximately 6 years after this version. The comma-parsing feature and the vulnerable code path (lib/parse.js with comma-split logic) do not exist in this version's architecture."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82562 does not affect version 0.5.1-tuxcare.1 of qs. not_affected \u2014 Target version 0.5.1 predates the `comma` option feature that enables parsing comma-separated values in query parameters. The vulnerability requires `comma: true` to trigger the arrayLimit bypass via bracket-key notation (e.g., `a[]=1,2,3,4`). Version 0.5.1 has no comma-parsing logic and treats such input as a single literal string value. The vulnerable code path (parseArrayValue with comma spl...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-82562"
      },
      "impact_statement": "not_affected \u2014 Target version 0.5.1 predates the `comma` option feature that enables parsing comma-separated values in query parameters. The vulnerability requires `comma: true` to trigger the arrayLimit bypass via bracket-key notation (e.g., `a[]=1,2,3,4`). Version 0.5.1 has no comma-parsing logic and treats such input as a single literal string value. The vulnerable code path (parseArrayValue with comma spl..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@0.5.1-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/qs@0.5.1-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8723 does not affect version 0.5.1-tuxcare.1 of qs. not_affected \u2014 Version 0.5.1 is not affected by CVE-2026-8723. The vulnerability requires both arrayFormat='comma' and encodeValuesOnly=true options, neither of which exist in version 0.5.1. The vulnerable code path that maps arrays through an encoder was introduced in 2021 (commit 4c4b23d, first released in v6.11.1), well after version 0.5.1 was released. Runtime testing confirms that v0.5.1 safely handles n...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-8723"
      },
      "impact_statement": "not_affected \u2014 Version 0.5.1 is not affected by CVE-2026-8723. The vulnerability requires both arrayFormat='comma' and encodeValuesOnly=true options, neither of which exist in version 0.5.1. The vulnerable code path that maps arrays through an encoder was introduced in 2021 (commit 4c4b23d, first released in v6.11.1), well after version 0.5.1 was released. Runtime testing confirms that v0.5.1 safely handles n..."
    }
  ]
}
