{
  "@id": "urn:uuid:20914221-342b-487d-9085-ee5ad4d9924b",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.5-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.5-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-15284 is fixed in version 6.5.5-tuxcare.2 of qs.",
      "vulnerability": {
        "name": "CVE-2025-15284"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.5-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.5-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2391 does not affect version 6.5.5-tuxcare.2 of qs. not_affected \u2014 Target version 6.5.5 does not contain the comma parsing feature required for this vulnerability. The comma option was introduced in v6.7.0, two minor versions after the target. Without comma parsing, comma-separated query parameter values remain as single strings and cannot bypass arrayLimit.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-2391"
      },
      "impact_statement": "not_affected \u2014 Target version 6.5.5 does not contain the comma parsing feature required for this vulnerability. The comma option was introduced in v6.7.0, two minor versions after the target. Without comma parsing, comma-separated query parameter values remain as single strings and cannot bypass arrayLimit."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.5-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.5-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82417 affects version 6.5.5-tuxcare.2 of qs.",
      "vulnerability": {
        "name": "CVE-2026-82417"
      },
      "action_statement": "Vulnerability CVE-2026-82417 affects version 6.5.5-tuxcare.2 of qs."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.5-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.5-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-82562 does not affect version 6.5.5-tuxcare.2 of qs. not_affected \u2014 Target version 6.5.5 is not affected by CVE-2026-82562. The vulnerability requires the comma-parsing feature (comma: true option, parseArrayValue function, and throwOnLimitExceeded option), which was introduced in v6.7.0. This version predates that feature by two minor versions and has none of the required components. Input like a[]=1,2,3,4 is treated as a single string value, not split into mu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-82562"
      },
      "impact_statement": "not_affected \u2014 Target version 6.5.5 is not affected by CVE-2026-82562. The vulnerability requires the comma-parsing feature (comma: true option, parseArrayValue function, and throwOnLimitExceeded option), which was introduced in v6.7.0. This version predates that feature by two minor versions and has none of the required components. Input like a[]=1,2,3,4 is treated as a single string value, not split into mu..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/qs@6.5.5-tuxcare.2",
          "identifiers": {
            "purl": "pkg:npm/qs@6.5.5-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8723 does not affect version 6.5.5-tuxcare.2 of qs. not_affected \u2014 Version 6.5.5 is not affected by CVE-2026-8723. The vulnerability requires the arrayFormat: 'comma' feature combined with encodeValuesOnly: true, which was introduced in v6.11.1. Version 6.5.5 lacks both the comma arrayFormat implementation and the utils.maybeMap function that the vulnerable code path relies on.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-8723"
      },
      "impact_statement": "not_affected \u2014 Version 6.5.5 is not affected by CVE-2026-8723. The vulnerability requires the arrayFormat: 'comma' feature combined with encodeValuesOnly: true, which was introduced in v6.11.1. Version 6.5.5 lacks both the comma arrayFormat implementation and the utils.maybeMap function that the vulnerable code path relies on."
    }
  ]
}
