{
  "@id": "urn:uuid:15006507-3e54-4d86-a9c3-4be47388adb1",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-1000048 does not affect version 4.0.0-tuxcare.2 of qs. already_fixed \u2014 CVE-2017-1000048 (Prototype Pollution) has been fixed in the target repository. The vulnerability was addressed by a TuxCare backport applied in commit bc776ca on January 26, 2026. The fix adds comprehensive prototype pollution protections to the qs.parse() function, including checks for Object.prototype properties and explicit __proto__ blocking. All defense mechanisms from the vendor patches ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2017-1000048"
      },
      "impact_statement": "already_fixed \u2014 CVE-2017-1000048 (Prototype Pollution) has been fixed in the target repository. The vulnerability was addressed by a TuxCare backport applied in commit bc776ca on January 26, 2026. The fix adds comprehensive prototype pollution protections to the qs.parse() function, including checks for Object.prototype properties and explicit __proto__ blocking. All defense mechanisms from the vendor patches ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24999 does not affect version 4.0.0-tuxcare.2 of qs. already_fixed \u2014 The target repository (qs version 4.0.0-tuxcare.1, SHA 7dbe1314675c0b5456f4a1254b1e63ea3e6b637b) already contains the fix for CVE-2022-24999. The defense against __proto__ prototype pollution has been applied in prior TuxCare backport commits (cb60809, dd207dd) as part of JSELS-728. The exact same defense mechanism from the upstream vendor patches is present in the target code.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-24999"
      },
      "impact_statement": "already_fixed \u2014 The target repository (qs version 4.0.0-tuxcare.1, SHA 7dbe1314675c0b5456f4a1254b1e63ea3e6b637b) already contains the fix for CVE-2022-24999. The defense against __proto__ prototype pollution has been applied in prior TuxCare backport commits (cb60809, dd207dd) as part of JSELS-728. The exact same defense mechanism from the upstream vendor patches is present in the target code."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15284 does not affect version 4.0.0-tuxcare.2 of qs. already_fixed \u2014 CVE-2025-15284 has been fixed in this version (4.0.0-tuxcare.1). The fix was applied via commit 0c1a397 (feat(JSELS-727): fix CVE-2025-15284), which adds arrayLimit enforcement to bracket notation parsing. The target code contains both the modified bracket notation handler in lib/parse.js that calls Utils.combine() with arrayLimit parameter, and the enhanced combine() function in lib/utils.js t...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-15284"
      },
      "impact_statement": "already_fixed \u2014 CVE-2025-15284 has been fixed in this version (4.0.0-tuxcare.1). The fix was applied via commit 0c1a397 (feat(JSELS-727): fix CVE-2025-15284), which adds arrayLimit enforcement to bracket notation parsing. The target code contains both the modified bracket notation handler in lib/parse.js that calls Utils.combine() with arrayLimit parameter, and the enhanced combine() function in lib/utils.js t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2391 does not affect version 4.0.0-tuxcare.2 of qs. not_affected \u2014 Version 4.0.0 is not affected by CVE-2026-2391. The vulnerability requires the 'comma' option feature (comma: true) which does not exist in this version. This feature was introduced in later versions (6.x+). Without the comma-parsing capability, query strings containing commas are treated as single string values rather than being split into arrays, preventing the unbounded array allocation vuln...",
      "vulnerability": {
        "name": "CVE-2026-2391"
      },
      "impact_statement": "not_affected \u2014 Version 4.0.0 is not affected by CVE-2026-2391. The vulnerability requires the 'comma' option feature (comma: true) which does not exist in this version. This feature was introduced in later versions (6.x+). Without the comma-parsing capability, query strings containing commas are treated as single string values rather than being split into arrays, preventing the unbounded array allocation vuln..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82417 affects version 4.0.0-tuxcare.2 of qs.",
      "vulnerability": {
        "name": "CVE-2026-82417"
      },
      "action_statement": "Vulnerability CVE-2026-82417 affects version 4.0.0-tuxcare.2 of qs."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82562 affects version 4.0.0-tuxcare.2 of qs.",
      "vulnerability": {
        "name": "CVE-2026-82562"
      },
      "action_statement": "Vulnerability CVE-2026-82562 affects version 4.0.0-tuxcare.2 of qs."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@4.0.0-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@4.0.0-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8723 does not affect version 4.0.0-tuxcare.2 of qs. not_affected \u2014 Target version 4.0.0 is NOT affected by CVE-2026-8723. The vulnerable code path (arrayFormat: 'comma' + encodeValuesOnly) does not exist in this version. The vulnerability was introduced in v6.11.1 (commit 4c4b23d, January 2023), years after v4.0.0. Empirical testing confirms the CVE PoC does not crash in v4.0.0.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-8723"
      },
      "impact_statement": "not_affected \u2014 Target version 4.0.0 is NOT affected by CVE-2026-8723. The vulnerable code path (arrayFormat: 'comma' + encodeValuesOnly) does not exist in this version. The vulnerability was introduced in v6.11.1 (commit 4c4b23d, January 2023), years after v4.0.0. Empirical testing confirms the CVE PoC does not crash in v4.0.0."
    }
  ]
}
