{
  "@id": "urn:uuid:4cc0f418-b99e-41d9-a2fb-38bbb75ceb17",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/serialize-javascript@1.9.1",
          "identifiers": {
            "purl": "pkg:npm/serialize-javascript@1.9.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-16769 affects version 1.9.1 of serialize-javascript, and is fixed in 1.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2019-16769"
      },
      "action_statement": "Vulnerability CVE-2019-16769 affects version 1.9.1 of serialize-javascript, and is fixed in 1.9.1-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/serialize-javascript@1.9.1",
          "identifiers": {
            "purl": "pkg:npm/serialize-javascript@1.9.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-7660 affects version 1.9.1 of serialize-javascript, and is fixed in 1.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2020-7660"
      },
      "action_statement": "Vulnerability CVE-2020-7660 affects version 1.9.1 of serialize-javascript, and is fixed in 1.9.1-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/serialize-javascript@1.9.1",
          "identifiers": {
            "purl": "pkg:npm/serialize-javascript@1.9.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34043 does not affect version 1.9.1 of serialize-javascript. not_affected \u2014 Version 1.9.1-tuxcare.1 is not affected by CVE-2026-34043. The vulnerable sparse array detection code (using instanceof Array and .filter()) was introduced in v5.0.0, several versions after 1.9.1. This version does not contain the code pattern that could cause CPU exhaustion when processing array-like objects with large length properties.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34043"
      },
      "impact_statement": "not_affected \u2014 Version 1.9.1-tuxcare.1 is not affected by CVE-2026-34043. The vulnerable sparse array detection code (using instanceof Array and .filter()) was introduced in v5.0.0, several versions after 1.9.1. This version does not contain the code pattern that could cause CPU exhaustion when processing array-like objects with large length properties."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/serialize-javascript@1.9.1",
          "identifiers": {
            "purl": "pkg:npm/serialize-javascript@1.9.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5c6j-r48x-rmvq affects version 1.9.1 of serialize-javascript, and is fixed in 1.9.1-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-5c6j-r48x-rmvq"
      },
      "action_statement": "Vulnerability GHSA-5c6j-r48x-rmvq affects version 1.9.1 of serialize-javascript, and is fixed in 1.9.1-tuxcare.1."
    }
  ]
}
