{
  "@id": "urn:uuid:e1e475df-df93-4b1a-b9a9-e54b5ae6fd05",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-03T11:50:02.760921+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2025-22150 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2025-22150"
      },
      "action_statement": "Vulnerability CVE-2025-22150 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2025-47279 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2025-47279"
      },
      "action_statement": "Vulnerability CVE-2025-47279 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-11525 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-11525"
      },
      "action_statement": "Vulnerability CVE-2026-11525 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-12151 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-12151"
      },
      "action_statement": "Vulnerability CVE-2026-12151 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-15157 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-15157"
      },
      "action_statement": "Vulnerability CVE-2026-15157 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-1525 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-1525"
      },
      "action_statement": "Vulnerability CVE-2026-1525 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T22:53:00.070822+00:00",
      "status_notes": "Vulnerability CVE-2026-1526 affects version 6.19.5-tuxcare.1 of undici.",
      "vulnerability": {
        "name": "CVE-2026-1526"
      },
      "action_statement": "Vulnerability CVE-2026-1526 affects version 6.19.5-tuxcare.1 of undici."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-1527 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-1527"
      },
      "action_statement": "Vulnerability CVE-2026-1527 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-1528 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-1528"
      },
      "action_statement": "Vulnerability CVE-2026-1528 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-16728 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-16728"
      },
      "action_statement": "Vulnerability CVE-2026-16728 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:49:00.929976+00:00",
      "status_notes": "Vulnerability CVE-2026-16729 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-16729"
      },
      "action_statement": "Vulnerability CVE-2026-16729 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T22:53:00.070822+00:00",
      "status_notes": "Vulnerability CVE-2026-18540 affects version 6.19.5-tuxcare.1 of undici.",
      "vulnerability": {
        "name": "CVE-2026-18540"
      },
      "action_statement": "Vulnerability CVE-2026-18540 affects version 6.19.5-tuxcare.1 of undici."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T22:53:00.070822+00:00",
      "status_notes": "Vulnerability CVE-2026-19534 is fixed in version 6.19.5-tuxcare.1 of undici.",
      "vulnerability": {
        "name": "CVE-2026-19534"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-03T11:50:02.760921+00:00",
      "status_notes": "Vulnerability CVE-2026-22036 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-22036"
      },
      "action_statement": "Vulnerability CVE-2026-22036 affects version 6.19.5-tuxcare.1 of undici, and is fixed in 6.19.5-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T22:53:00.070822+00:00",
      "status_notes": "Vulnerability CVE-2026-2229 affects version 6.19.5-tuxcare.1 of undici.",
      "vulnerability": {
        "name": "CVE-2026-2229"
      },
      "action_statement": "Vulnerability CVE-2026-2229 affects version 6.19.5-tuxcare.1 of undici."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T22:53:00.070822+00:00",
      "status_notes": "Vulnerability CVE-2026-6733 affects version 6.19.5-tuxcare.1 of undici.",
      "vulnerability": {
        "name": "CVE-2026-6733"
      },
      "action_statement": "Vulnerability CVE-2026-6733 affects version 6.19.5-tuxcare.1 of undici."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/undici@6.19.5-tuxcare.1",
          "identifiers": {
            "purl": "pkg:npm/undici@6.19.5-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-10-01T22:53:00.070822+00:00",
      "status_notes": "Vulnerability CVE-2026-9679 does not affect version 6.19.5-tuxcare.1 of undici. not_affected \u2014 Target version 6.19.5 is not affected by CVE-2026-9679. The vulnerability (percent-decoding cookie values via querystring.unescape, enabling HTTP response header injection) was introduced in undici 7.0.0 via PR #3789 (commit dac8e73d, Oct 30 2024). The target is on a TuxCare maintenance branch that diverged from the upstream main branch before this vulnerability was introduced. The target's coo...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-9679"
      },
      "impact_statement": "not_affected \u2014 Target version 6.19.5 is not affected by CVE-2026-9679. The vulnerability (percent-decoding cookie values via querystring.unescape, enabling HTTP response header injection) was introduced in undici 7.0.0 via PR #3789 (commit dac8e73d, Oct 30 2024). The target is on a TuxCare maintenance branch that diverged from the upstream main branch before this vulnerability was introduced. The target's coo..."
    }
  ]
}
