{
  "@id": "urn:uuid:27cdb7f6-1b84-4b54-a370-8f392e3df3a5",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-8860 is fixed in version 1.0.3-tuxcare.1 of tar.",
      "vulnerability": {
        "name": "CVE-2015-8860"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-20834 is fixed in version 1.0.3-tuxcare.1 of tar.",
      "vulnerability": {
        "name": "CVE-2018-20834"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32804 is fixed in version 1.0.3-tuxcare.1 of tar.",
      "vulnerability": {
        "name": "CVE-2021-32804"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-37713 is fixed in version 1.0.3-tuxcare.1 of tar.",
      "vulnerability": {
        "name": "CVE-2021-37713"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28863 is fixed in version 1.0.3-tuxcare.1 of tar.",
      "vulnerability": {
        "name": "CVE-2024-28863"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-23745 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-23745"
      },
      "action_statement": "Vulnerability CVE-2026-23745 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-23950 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-23950"
      },
      "action_statement": "Vulnerability CVE-2026-23950 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24842 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-24842"
      },
      "action_statement": "Vulnerability CVE-2026-24842 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-26960 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-26960"
      },
      "action_statement": "Vulnerability CVE-2026-26960 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29786 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-29786"
      },
      "action_statement": "Vulnerability CVE-2026-29786 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31802 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-31802"
      },
      "action_statement": "Vulnerability CVE-2026-31802 affects version 1.0.3-tuxcare.1 of tar, and is fixed in 1.0.3-tuxcare.3."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-53655 does not affect version 1.0.3-tuxcare.1 of tar. not_affected \u2014 The target repository (node-tar v1.0.3-tuxcare.3) is NOT AFFECTED by CVE-2026-53655. While the target is the same product (node-tar) and does parse PAX extended headers, the vulnerability pattern does not exist due to fundamental architectural differences. In v1.0.3, header decoding never receives or applies PAX extended header overrides - metadata entries explicitly receive null for extended p...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53655"
      },
      "impact_statement": "not_affected \u2014 The target repository (node-tar v1.0.3-tuxcare.3) is NOT AFFECTED by CVE-2026-53655. While the target is the same product (node-tar) and does parse PAX extended headers, the vulnerability pattern does not exist due to fundamental architectural differences. In v1.0.3, header decoding never receives or applies PAX extended header overrides - metadata entries explicitly receive null for extended p..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59871 does not affect version 1.0.3-tuxcare.1 of tar. not_affected \u2014 CVE-2026-59871 describes a vulnerability in node-tar where PAX header values matching /^[0-9]+$/ are coerced to numbers, causing TypeErrors when .split() is called. This vulnerability does NOT affect version 1.0.3 because it uses field-name-based numeric coercion that explicitly excludes 'path' and 'linkpath' fields. The CVE describes a TypeScript version with value-based regex matching, while ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59871"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-59871 describes a vulnerability in node-tar where PAX header values matching /^[0-9]+$/ are coerced to numbers, causing TypeErrors when .split() is called. This vulnerability does NOT affect version 1.0.3 because it uses field-name-based numeric coercion that explicitly excludes 'path' and 'linkpath' fields. The CVE describes a TypeScript version with value-based regex matching, while ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59873 does not affect version 1.0.3-tuxcare.1 of tar. Version 1.0.3 is NOT affected by CVE-2026-59873. This vulnerability concerns decompression bombs in gzip/brotli/zstd-compressed TAR archives. Version 1.0.3 does not have any integrated decompression capability - it only processes raw TAR format data. The vulnerable code (zlib.Unzip/BrotliDecompress handling with unlimited decompression ratio) does not exist in this version. Users must decompress .tar.gz files externally before passing to this library, making the integrated decompression attack vector absent.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59873"
      },
      "impact_statement": "Version 1.0.3 is NOT affected by CVE-2026-59873. This vulnerability concerns decompression bombs in gzip/brotli/zstd-compressed TAR archives. Version 1.0.3 does not have any integrated decompression capability - it only processes raw TAR format data. The vulnerable code (zlib.Unzip/BrotliDecompress handling with unlimited decompression ratio) does not exist in this version. Users must decompress .tar.gz files externally before passing to this library, making the integrated decompression attack vector absent."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59874 does not affect version 1.0.3-tuxcare.1 of tar. not_affected \u2014 Target version 1.0.3 does not have the tar.replace() API that contains the vulnerability described in CVE-2026-59874. The replace() function was introduced in later versions (6.x+). The CVE PoC would fail immediately with 'TypeError: tar.replace is not a function' in version 1.0.3.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59874"
      },
      "impact_statement": "not_affected \u2014 Target version 1.0.3 does not have the tar.replace() API that contains the vulnerability described in CVE-2026-59874. The replace() function was introduced in later versions (6.x+). The CVE PoC would fail immediately with 'TypeError: tar.replace is not a function' in version 1.0.3."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59875 does not affect version 1.0.3-tuxcare.1 of tar. already_fixed \u2014 Version 1.0.3 contains a comprehensive NUL-byte sanitization defense in lib/entry.js (lines 164-168) that strips embedded NUL bytes from both path and linkpath fields before they reach filesystem operations. This defense was added in commit 0444d88 (November 2011) and blocks the CVE-2026-59875 attack vector completely. The target exhibits the upstream fix's behavior using .split(\"\\0\")[0], which...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59875"
      },
      "impact_statement": "already_fixed \u2014 Version 1.0.3 contains a comprehensive NUL-byte sanitization defense in lib/entry.js (lines 164-168) that strips embedded NUL bytes from both path and linkpath fields before they reach filesystem operations. This defense was added in commit 0444d88 (November 2011) and blocks the CVE-2026-59875 attack vector completely. The target exhibits the upstream fix's behavior using .split(\"\\0\")[0], which..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-73566 does not affect version 1.0.3-tuxcare.1 of tar. not_affected \u2014 Version 1.0.3 is not affected by CVE-2026-73566. The vulnerability requires the `filesFilter` member-selection mechanism with its recursive `mapHas` helper, which was introduced in later versions of node-tar (TypeScript rewrite, modern async API). Version 1.0.3 is a much older JavaScript-based implementation with a streaming API (Parse/Extract) that has no member-selection capability, no `files...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-73566"
      },
      "impact_statement": "not_affected \u2014 Version 1.0.3 is not affected by CVE-2026-73566. The vulnerability requires the `filesFilter` member-selection mechanism with its recursive `mapHas` helper, which was introduced in later versions of node-tar (TypeScript rewrite, modern async API). Version 1.0.3 is a much older JavaScript-based implementation with a streaming API (Parse/Extract) that has no member-selection capability, no `files..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tar@1.0.3-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/tar@1.0.3-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-r292-9mhp-454m does not affect version 1.0.3-tuxcare.1 of tar. not_affected \u2014 Version 1.0.3 is not affected by GHSA-r292-9mhp-454m. The vulnerability requires the member-selection API (tar.t([files]) or tar.x({...}, [files])) and the filesFilter/mapHas code path, which were introduced in versions after 1.0.3. The vulnerable src/list.ts module with the recursive mapHas helper does not exist in this version.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-r292-9mhp-454m"
      },
      "impact_statement": "not_affected \u2014 Version 1.0.3 is not affected by GHSA-r292-9mhp-454m. The vulnerability requires the member-selection API (tar.t([files]) or tar.x({...}, [files])) and the filesFilter/mapHas code path, which were introduced in versions after 1.0.3. The vulnerable src/list.ts module with the recursive mapHas helper does not exist in this version."
    }
  ]
}
