{
  "@id": "urn:uuid:8b23a129-a971-4f66-9f9e-ba2129692c0b",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tough-cookie@2.2.2",
          "identifiers": {
            "purl": "pkg:npm/tough-cookie@2.2.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-1000232 affects version 2.2.2 of tough-cookie, and is fixed in 2.2.2-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2016-1000232"
      },
      "action_statement": "Vulnerability CVE-2016-1000232 affects version 2.2.2 of tough-cookie, and is fixed in 2.2.2-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tough-cookie@2.2.2",
          "identifiers": {
            "purl": "pkg:npm/tough-cookie@2.2.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-15010 affects version 2.2.2 of tough-cookie, and is fixed in 2.2.2-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2017-15010"
      },
      "action_statement": "Vulnerability CVE-2017-15010 affects version 2.2.2 of tough-cookie, and is fixed in 2.2.2-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tough-cookie@2.2.2",
          "identifiers": {
            "purl": "pkg:npm/tough-cookie@2.2.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32804 is a false positive for tough-cookie 2.2.2. false_positive \u2014 CVE-2021-32804 is a wrong-project match. The CVE concerns the npm package 'tar' (node-tar), a tar archive extraction library with path sanitization vulnerabilities. The target repository is 'tough-cookie' version 2.2.2, an RFC6265 cookie parsing and management library. These are completely different projects with no code relationship.",
      "vulnerability": {
        "name": "CVE-2021-32804"
      },
      "impact_statement": "false_positive \u2014 CVE-2021-32804 is a wrong-project match. The CVE concerns the npm package 'tar' (node-tar), a tar archive extraction library with path sanitization vulnerabilities. The target repository is 'tough-cookie' version 2.2.2, an RFC6265 cookie parsing and management library. These are completely different projects with no code relationship."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tough-cookie@2.2.2",
          "identifiers": {
            "purl": "pkg:npm/tough-cookie@2.2.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-37713 is a false positive for tough-cookie 2.2.2. false_positive \u2014 CVE-2021-37713 concerns the npm package 'tar' (node-tar), a tar archive extraction library. The target repository is 'tough-cookie' version 2.2.2, an HTTP cookie parsing library (RFC6265). These are completely different npm packages with different purposes. The tar package is not present in this repository as the project itself, as vendored code, or as a dependency. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2021-37713"
      },
      "impact_statement": "false_positive \u2014 CVE-2021-37713 concerns the npm package 'tar' (node-tar), a tar archive extraction library. The target repository is 'tough-cookie' version 2.2.2, an HTTP cookie parsing library (RFC6265). These are completely different npm packages with different purposes. The tar package is not present in this repository as the project itself, as vendored code, or as a dependency. This is a wrong-project match."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/tough-cookie@2.2.2",
          "identifiers": {
            "purl": "pkg:npm/tough-cookie@2.2.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-26136 affects version 2.2.2 of tough-cookie, and is fixed in 2.2.2-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2023-26136"
      },
      "action_statement": "Vulnerability CVE-2023-26136 affects version 2.2.2 of tough-cookie, and is fixed in 2.2.2-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/tough-cookie@2.2.2",
          "identifiers": {
            "purl": "pkg:npm/tough-cookie@2.2.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28863 is a false positive for tough-cookie 2.2.2. false_positive \u2014 CVE-2024-28863 is a wrong-project match. The advisory concerns node-tar (a tar archive extraction library), but the target repository is tough-cookie version 2.2.2 (an RFC6265 cookie parsing library). The affected component's code is completely absent from the entire repository.",
      "vulnerability": {
        "name": "CVE-2024-28863"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-28863 is a wrong-project match. The advisory concerns node-tar (a tar archive extraction library), but the target repository is tough-cookie version 2.2.2 (an RFC6265 cookie parsing library). The affected component's code is completely absent from the entire repository."
    }
  ]
}
