{
  "@id": "urn:uuid:cdeb7b64-56de-4498-8657-fb11223e0bba",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T18:46:58.638266+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10065 is fixed in version 5.29.0-tuxcare.4 of undici.",
      "vulnerability": {
        "name": "AIKIDO-2024-10065"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24750 does not affect version 5.29.0-tuxcare.4 of undici. not_affected \u2014 Version 5.29.0 is NOT AFFECTED by CVE-2024-24750. The vulnerable byteStream code pattern (push-based reading with unbounded buffering) was introduced in undici v6.0.0 (Dec 2023, commit af9aaea0) and fixed in v6.6.1 (Feb 2024, commit 87a48113). Version 5.29.0 predates this architectural change and uses a different implementation with proper pull-based reading and backpressure control. The vulner...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-24750"
      },
      "impact_statement": "not_affected \u2014 Version 5.29.0 is NOT AFFECTED by CVE-2024-24750. The vulnerable byteStream code pattern (push-based reading with unbounded buffering) was introduced in undici v6.0.0 (Dec 2023, commit af9aaea0) and fixed in v6.6.1 (Feb 2024, commit 87a48113). Version 5.29.0 predates this architectural change and uses a different implementation with proper pull-based reading and backpressure control. The vulner..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24758 does not affect version 5.29.0-tuxcare.4 of undici. not_affected \u2014 CVE-2024-24758 (proxy-authorization header leak on cross-origin redirects) is NOT present in undici 5.29.0-tuxcare.4. The fix was already included in upstream v5.29.0 (released before TuxCare's maintenance began). The defensive code `request.headersList.delete('proxy-authorization', true)` exists at lib/fetch/index.js:1207, authored by upstream maintainer Matteo Collina (hello@matteocollina.com...",
      "vulnerability": {
        "name": "CVE-2024-24758"
      },
      "impact_statement": "not_affected \u2014 CVE-2024-24758 (proxy-authorization header leak on cross-origin redirects) is NOT present in undici 5.29.0-tuxcare.4. The fix was already included in upstream v5.29.0 (released before TuxCare's maintenance began). The defensive code `request.headersList.delete('proxy-authorization', true)` exists at lib/fetch/index.js:1207, authored by upstream maintainer Matteo Collina (hello@matteocollina.com..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-11525 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-11525"
      },
      "action_statement": "Vulnerability CVE-2026-11525 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.5."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12151 does not affect version 5.29.0-tuxcare.4 of undici. Version 5.29.0 is not vulnerable. Summary: CVE-2026-12151 does not affect this version. The CVE explicitly states 'All releases starting at undici 6.17.0 are affected', and the target is undici 5.29.0-tuxcare.4, which predates the first affected version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-12151"
      },
      "impact_statement": "Version 5.29.0 is not vulnerable. Summary: CVE-2026-12151 does not affect this version. The CVE explicitly states 'All releases starting at undici 6.17.0 are affected', and the target is undici 5.29.0-tuxcare.4, which predates the first affected version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-15157 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-15157"
      },
      "action_statement": "Vulnerability CVE-2026-15157 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.6."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1525 is fixed in version 5.29.0-tuxcare.4 of undici.",
      "vulnerability": {
        "name": "CVE-2026-1525"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1526 does not affect version 5.29.0-tuxcare.4 of undici. not_affected \u2014 analysis-only patch file patches/CVE-2026-1526.patch on tuxcare-current/5.29.0 in els-js/undici documents that CVE-2026-1526 does not affect this version (no code change applied).",
      "vulnerability": {
        "name": "CVE-2026-1526"
      },
      "impact_statement": "not_affected \u2014 analysis-only patch file patches/CVE-2026-1526.patch on tuxcare-current/5.29.0 in els-js/undici documents that CVE-2026-1526 does not affect this version (no code change applied)."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1527 is fixed in version 5.29.0-tuxcare.4 of undici.",
      "vulnerability": {
        "name": "CVE-2026-1527"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-16728 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-16728"
      },
      "action_statement": "Vulnerability CVE-2026-16728 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.6."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-16729 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.6.",
      "vulnerability": {
        "name": "CVE-2026-16729"
      },
      "action_statement": "Vulnerability CVE-2026-16729 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.6."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-29T18:46:58.638266+00:00",
      "status_notes": "Vulnerability CVE-2026-18540 affects version 5.29.0-tuxcare.4 of undici.",
      "vulnerability": {
        "name": "CVE-2026-18540"
      },
      "action_statement": "Vulnerability CVE-2026-18540 affects version 5.29.0-tuxcare.4 of undici."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22036 is fixed in version 5.29.0-tuxcare.4 of undici.",
      "vulnerability": {
        "name": "CVE-2026-22036"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2229 is fixed in version 5.29.0-tuxcare.4 of undici.",
      "vulnerability": {
        "name": "CVE-2026-2229"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6733 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.5.",
      "vulnerability": {
        "name": "CVE-2026-6733"
      },
      "action_statement": "Vulnerability CVE-2026-6733 affects version 5.29.0-tuxcare.4 of undici, and is fixed in 5.29.0-tuxcare.5."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.29.0-tuxcare.4",
          "identifiers": {
            "purl": "pkg:npm/undici@5.29.0-tuxcare.4"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9679 does not affect version 5.29.0-tuxcare.4 of undici. not_affected \u2014 Target version 5.29.0-tuxcare.4 is not affected. The vulnerability was introduced in undici v7.0.0 via PR #3789, which added percent-decoding (qsUnescape) to cookie values. The target version predates this change and does not perform percent-decoding, returning cookie values unmodified.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-9679"
      },
      "impact_statement": "not_affected \u2014 Target version 5.29.0-tuxcare.4 is not affected. The vulnerability was introduced in undici v7.0.0 via PR #3789, which added percent-decoding (qsUnescape) to cookie values. The target version predates this change and does not perform percent-decoding, returning cookie values unmodified."
    }
  ]
}
