{
  "@id": "urn:uuid:41c7a396-4734-4459-a361-63a3fbfa6fc0",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T19:41:36.034129+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31150 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2022-31150"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31151 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2022-31151"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-35948 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2022-35948"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-35949 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2022-35949"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23936 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2023-23936"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24807 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2023-24807"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45143 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2023-45143"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24750 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 Version 5.5.1 is NOT affected by CVE-2024-24750. The vulnerable code pattern (byte streams with async start controller and while(true) eager pushing) was introduced 2939 commits later in v6.0.0 (commit af9aaea0, December 2023) and fixed in v6.6.1 (commit 87a48113, February 2024). Version 5.5.1 uses a fundamentally different architecture with pull-based ReadableStreams that have inherent backpre...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2024-24750"
      },
      "impact_statement": "not_affected \u2014 Version 5.5.1 is NOT affected by CVE-2024-24750. The vulnerable code pattern (byte streams with async start controller and while(true) eager pushing) was introduced 2939 commits later in v6.0.0 (commit af9aaea0, December 2023) and fixed in v6.6.1 (commit 87a48113, February 2024). Version 5.5.1 uses a fundamentally different architecture with pull-based ReadableStreams that have inherent backpre..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24758 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2024-24758"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30260 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2024-30260"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30261 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 Version 5.5.1 is not affected by CVE-2024-30261. The vulnerable integrity parsing and validation code does not exist in this version. The integrity checking feature was implemented starting in v5.10.0 with a flawed regex pattern that was later fixed in v5.28.4. Version 5.5.1 only contains a stub function `matchRequestIntegrity` that unconditionally returns `false`, causing all integrity-checked...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-30261"
      },
      "impact_statement": "not_affected \u2014 Version 5.5.1 is not affected by CVE-2024-30261. The vulnerable integrity parsing and validation code does not exist in this version. The integrity checking feature was implemented starting in v5.10.0 with a flawed regex pattern that was later fixed in v5.28.4. Version 5.5.1 only contains a stub function `matchRequestIntegrity` that unconditionally returns `false`, causing all integrity-checked..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22150 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2025-22150"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-47279 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2025-47279"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-11525 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 The target (undici v5.5.1) is NOT AFFECTED by CVE-2026-11525. The vulnerability was introduced in undici v5.15.0 when the cookie parsing feature was added via commit 7ee93b26. Version 5.5.1 predates this feature introduction and does not contain any cookie parsing code. The vulnerable code path (lib/cookies/parse.js or lib/web/cookies/parse.js with substring-based SameSite matching) does not ex...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-11525"
      },
      "impact_statement": "not_affected \u2014 The target (undici v5.5.1) is NOT AFFECTED by CVE-2026-11525. The vulnerability was introduced in undici v5.15.0 when the cookie parsing feature was added via commit 7ee93b26. Version 5.5.1 predates this feature introduction and does not contain any cookie parsing code. The vulnerable code path (lib/cookies/parse.js or lib/web/cookies/parse.js with substring-based SameSite matching) does not ex..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-12151 does not affect version 5.5.1-tuxcare.3 of undici. Undici version 5.5.1 does not contain any WebSocket client implementation. The vulnerable code pattern (unbounded WebSocket fragment accumulation in ByteParser) cannot exist because the WebSocket client functionality (lib/web/websocket/, ByteParser class, frame parsing logic) was introduced after version 5.5.1. Git history confirms WebSocket code first appeared in version 6.11.1+. The CVE affects \"undici >= 6.17.0\" and while version metadata alone is not conclusive, exhaustive code search confirms the WebSocket client code is genuinely absent from 5.5.1. The INPUT (WebSocket continuation frames) cannot be received by this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-12151"
      },
      "impact_statement": "Undici version 5.5.1 does not contain any WebSocket client implementation. The vulnerable code pattern (unbounded WebSocket fragment accumulation in ByteParser) cannot exist because the WebSocket client functionality (lib/web/websocket/, ByteParser class, frame parsing logic) was introduced after version 5.5.1. Git history confirms WebSocket code first appeared in version 6.11.1+. The CVE affects \"undici >= 6.17.0\" and while version metadata alone is not conclusive, exhaustive code search confirms the WebSocket client code is genuinely absent from 5.5.1. The INPUT (WebSocket continuation frames) cannot be received by this version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-15157 affects version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-15157"
      },
      "action_statement": "Vulnerability CVE-2026-15157 affects version 5.5.1-tuxcare.3 of undici."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1525 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-1525"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1526 affects version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-1526"
      },
      "action_statement": "Vulnerability CVE-2026-1526 affects version 5.5.1-tuxcare.3 of undici."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1527 affects version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-1527"
      },
      "action_statement": "Vulnerability CVE-2026-1527 affects version 5.5.1-tuxcare.3 of undici."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-16728 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 Target version 5.5.1 is not affected by CVE-2026-16728. The vulnerability requires interceptors.retry() functionality, which does not exist in this version. The retry handler feature (lib/handler/retry-handler.js) was introduced in commit f9960147 on 2023-11-13 and first appeared in v5.28.0, significantly after v5.5.1 was released. Without the retry handler, the vulnerable code path\u2014where Conte...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-16728"
      },
      "impact_statement": "not_affected \u2014 Target version 5.5.1 is not affected by CVE-2026-16728. The vulnerability requires interceptors.retry() functionality, which does not exist in this version. The retry handler feature (lib/handler/retry-handler.js) was introduced in commit f9960147 on 2023-11-13 and first appeared in v5.28.0, significantly after v5.5.1 was released. Without the retry handler, the vulnerable code path\u2014where Conte..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-16729 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 Version 5.5.1 is not affected by CVE-2026-16729. The vulnerable cookie validation module (lib/web/cookies/util.js containing setCookie, validateCookieDomain, and unparsed attribute handling) was introduced in version 5.23.0 (commit 7ee93b26, 2023-01-06). Version 5.5.1 predates this feature by multiple releases and contains no cookie parsing, validation, or attribute injection attack surface. Th...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-16729"
      },
      "impact_statement": "not_affected \u2014 Version 5.5.1 is not affected by CVE-2026-16729. The vulnerable cookie validation module (lib/web/cookies/util.js containing setCookie, validateCookieDomain, and unparsed attribute handling) was introduced in version 5.23.0 (commit 7ee93b26, 2023-01-06). Version 5.5.1 predates this feature by multiple releases and contains no cookie parsing, validation, or attribute injection attack surface. Th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-29T19:41:36.034129+00:00",
      "status_notes": "Vulnerability CVE-2026-18540 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 CVE-2026-18540 affects undici's interceptors.retry() functionality, which can resume partial HTTP responses and append resumed bytes to an already-exposed response body, causing the delivered body to exceed the original Content-Length. The target version 5.5.1-tuxcare.3 does NOT have the retry interceptor functionality at all. The retry handler (lib/handler/retry-handler.js) and interceptor API...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-18540"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-18540 affects undici's interceptors.retry() functionality, which can resume partial HTTP responses and append resumed bytes to an already-exposed response body, causing the delivered body to exceed the original Content-Length. The target version 5.5.1-tuxcare.3 does NOT have the retry interceptor functionality at all. The retry handler (lib/handler/retry-handler.js) and interceptor API..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22036 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-22036"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2229 affects version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-2229"
      },
      "action_statement": "Vulnerability CVE-2026-2229 affects version 5.5.1-tuxcare.3 of undici."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6733 is fixed in version 5.5.1-tuxcare.3 of undici.",
      "vulnerability": {
        "name": "CVE-2026-6733"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@5.5.1-tuxcare.3",
          "identifiers": {
            "purl": "pkg:npm/undici@5.5.1-tuxcare.3"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9679 does not affect version 5.5.1-tuxcare.3 of undici. not_affected \u2014 The target version undici 5.5.1 does not contain the vulnerable cookie parsing functionality. The parseSetCookie/parseCookie/getSetCookies functions and the lib/web/cookies/parse.js file that would contain the percent-decoding vulnerability do not exist in this version. Cookie parsing was first introduced in v5.15.0 (without the vulnerability), the vulnerability was introduced in v7.0.0 via com...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-9679"
      },
      "impact_statement": "not_affected \u2014 The target version undici 5.5.1 does not contain the vulnerable cookie parsing functionality. The parseSetCookie/parseCookie/getSetCookies functions and the lib/web/cookies/parse.js file that would contain the percent-decoding vulnerability do not exist in this version. Cookie parsing was first introduced in v5.15.0 (without the vulnerability), the vulnerability was introduced in v7.0.0 via com..."
    }
  ]
}
