{
  "@id": "urn:uuid:6106c41b-8152-40f8-acfb-af02e173f025",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/serialize-javascript@3.1.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/serialize-javascript@3.1.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34043 does not affect version 3.1.0-tuxcare.1 of serialize-javascript. not_affected \u2014 Version 3.1.0 is NOT affected by CVE-2026-34043. The vulnerable sparse array detection code (using `instanceof Array` and `.filter()`) was introduced in commit 96431aa after v5.0.0, well after the target version 3.1.0. The vulnerability only affects versions 5.0.1 through 7.0.4. Version 3.1.0 delegates array serialization to native JSON.stringify without custom sparse array handling, making the...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-34043"
      },
      "impact_statement": "not_affected \u2014 Version 3.1.0 is NOT affected by CVE-2026-34043. The vulnerable sparse array detection code (using `instanceof Array` and `.filter()`) was introduced in commit 96431aa after v5.0.0, well after the target version 3.1.0. The vulnerability only affects versions 5.0.1 through 7.0.4. Version 3.1.0 delegates array serialization to native JSON.stringify without custom sparse array handling, making the..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/serialize-javascript@3.1.0-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/serialize-javascript@3.1.0-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5c6j-r48x-rmvq is fixed in version 3.1.0-tuxcare.1 of serialize-javascript.",
      "vulnerability": {
        "name": "GHSA-5c6j-r48x-rmvq"
      }
    }
  ]
}
