{
  "@id": "urn:uuid:de3e5a7e-a1ee-4315-bdac-efc172bb5a63",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.3",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15284 affects version 6.5.3 of qs, and is fixed in 6.5.3-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2025-15284"
      },
      "action_statement": "Vulnerability CVE-2025-15284 affects version 6.5.3 of qs, and is fixed in 6.5.3-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.3",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2391 does not affect version 6.5.3 of qs. Version 6.5.3 is not vulnerable. Summary: The target repository (qs v6.5.3-tuxcare.1) is NOT vulnerable to CVE-2026-2391 because it does not contain the comma parsing feature that is affected by this vulnerability. The comma option was introduced in qs v6.10.0, while this repository is running v6.5.3, which predates that feature by several major releases. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2391"
      },
      "impact_statement": "Version 6.5.3 is not vulnerable. Summary: The target repository (qs v6.5.3-tuxcare.1) is NOT vulnerable to CVE-2026-2391 because it does not contain the comma parsing feature that is affected by this vulnerability. The comma option was introduced in qs v6.10.0, while this repository is running v6.5.3, which predates that feature by several major releases. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.3",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82417 affects version 6.5.3 of qs.",
      "vulnerability": {
        "name": "CVE-2026-82417"
      },
      "action_statement": "Vulnerability CVE-2026-82417 affects version 6.5.3 of qs."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.3",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82562 does not affect version 6.5.3 of qs. not_affected \u2014 The target version (6.5.3) is not affected by CVE-2026-82562. The vulnerability requires the comma-parsing feature (`comma: true` option) which was introduced in v6.7.0, two minor versions after the target. Without this feature, the specific arrayLimit bypass described in the CVE cannot occur. This is Rule 5 Type A1: the INPUT type (comma-separated values parsed as arrays) is not received anywh...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-82562"
      },
      "impact_statement": "not_affected \u2014 The target version (6.5.3) is not affected by CVE-2026-82562. The vulnerability requires the comma-parsing feature (`comma: true` option) which was introduced in v6.7.0, two minor versions after the target. Without this feature, the specific arrayLimit bypass described in the CVE cannot occur. This is Rule 5 Type A1: the INPUT type (comma-separated values parsed as arrays) is not received anywh..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.3",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8723 affects version 6.5.3 of qs.",
      "vulnerability": {
        "name": "CVE-2026-8723"
      },
      "action_statement": "Vulnerability CVE-2026-8723 affects version 6.5.3 of qs."
    }
  ]
}
