{
  "@id": "urn:uuid:0ffdcb4d-1be8-4c02-b356-3103692560ca",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-26T21:35:00.556680+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/sharp@0.27.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/sharp@0.27.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29256 is fixed in version 0.27.2-tuxcare.1 of sharp.",
      "vulnerability": {
        "name": "CVE-2022-29256"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/sharp@0.27.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/sharp@0.27.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-26T21:35:00.556680+00:00",
      "status_notes": "Vulnerability GHSA-54xq-cgqr-rpm3 affects version 0.27.2-tuxcare.1 of sharp, and is fixed in 0.27.2-tuxcare.2.",
      "vulnerability": {
        "name": "GHSA-54xq-cgqr-rpm3"
      },
      "action_statement": "Vulnerability GHSA-54xq-cgqr-rpm3 affects version 0.27.2-tuxcare.1 of sharp, and is fixed in 0.27.2-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/sharp@0.27.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/sharp@0.27.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability GHSA-f88m-g3jw-g9cj affects version 0.27.2-tuxcare.1 of sharp and will not be fixed. Not fixable in sharp's own code - CVE-2026-33327/33328/35590/35591 live in native GIF/TIFF/VIPS codecs inside the prebuilt libvips binary, not in sharp's JS/C++. Upstream fix is libvips 8.18.3 (sharp 0.35.0). sharp 0.27.2 pins libvips 8.10.5, and the prebuilt-libvips download channel it uses was retired after 8.14 (v8.15+/8.18 return 404; libvips is now shipped only as runtime-only @img/sharp-libvips-* npm packages without build headers). Backporting 8.18 to 0.27.2 would require re-wiring libvips acquisition/build (vendoring the .so + headers or Nexus mirroring, plus binding.gyp/install changes) - substantial manual work for an EOL line. Marked won't fix. Mitigation: avoid processing untrusted GIF/TIFF/VIPS input, or use a sharp release built on libvips >= 8.18.3.",
      "vulnerability": {
        "name": "GHSA-f88m-g3jw-g9cj"
      },
      "action_statement": "Vulnerability GHSA-f88m-g3jw-g9cj affects version 0.27.2-tuxcare.1 of sharp and will not be fixed. Not fixable in sharp's own code - CVE-2026-33327/33328/35590/35591 live in native GIF/TIFF/VIPS codecs inside the prebuilt libvips binary, not in sharp's JS/C++. Upstream fix is libvips 8.18.3 (sharp 0.35.0). sharp 0.27.2 pins libvips 8.10.5, and the prebuilt-libvips download channel it uses was retired after 8.14 (v8.15+/8.18 return 404; libvips is now shipped only as runtime-only @img/sharp-libvips-* npm packages without build headers). Backporting 8.18 to 0.27.2 would require re-wiring libvips acquisition/build (vendoring the .so + headers or Nexus mirroring, plus binding.gyp/install changes) - substantial manual work for an EOL line. Marked won't fix. Mitigation: avoid processing untrusted GIF/TIFF/VIPS input, or use a sharp release built on libvips >= 8.18.3."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/sharp@0.27.2-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/sharp@0.27.2-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-rgj7-g3m4-5g8c does not affect version 0.27.2-tuxcare.1 of sharp. not_affected \u2014 The target repository (sharp v0.27.2) is not affected because the vulnerability exists in libheif, an external C library for HEIF/AVIF image decoding. Sharp's source code contains no libheif implementation\u2014only JavaScript APIs and C++ bindings that delegate image processing to libvips (which in turn uses libheif). The vulnerable code is present only in prebuilt libvips binaries downloaded at in...",
      "vulnerability": {
        "name": "GHSA-rgj7-g3m4-5g8c"
      },
      "impact_statement": "not_affected \u2014 The target repository (sharp v0.27.2) is not affected because the vulnerability exists in libheif, an external C library for HEIF/AVIF image decoding. Sharp's source code contains no libheif implementation\u2014only JavaScript APIs and C++ bindings that delegate image processing to libvips (which in turn uses libheif). The vulnerable code is present only in prebuilt libvips binaries downloaded at in..."
    }
  ]
}
