{
  "@id": "urn:uuid:c7e2a96f-10fc-414a-b5ab-a6f040b31a7f",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-26258 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent. already_fixed \u2014 CVE-2020-26258 has already been fixed in the target repository. The vendor patch commit 6740c04b217aef02d44fba26402b35e0f6f493ce is present, adding 'jdk.nashorn.internal.objects.NativeString' to the default blacklist in XStream's security framework. This prevents the Server-Side Request Forgery attack chain described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-26258"
      },
      "impact_statement": "already_fixed \u2014 CVE-2020-26258 has already been fixed in the target repository. The vendor patch commit 6740c04b217aef02d44fba26402b35e0f6f493ce is present, adding 'jdk.nashorn.internal.objects.NativeString' to the default blacklist in XStream's security framework. This prevents the Server-Side Request Forgery attack chain described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-26259 does not affect version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent. already_fixed \u2014 XStream version 1.4.17 already contains a fix for CVE-2020-26259. The target has an even stronger defense than the original 1.4.15 fix: it denies the entire InputStream type hierarchy, which comprehensively blocks ReadAllStream$FileStream and all other malicious InputStream subclasses.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-26259"
      },
      "impact_statement": "already_fixed \u2014 XStream version 1.4.17 already contains a fix for CVE-2020-26259. The target has an even stronger defense than the original 1.4.15 fix: it denies the entire InputStream type hierarchy, which comprehensively blocks ReadAllStream$FileStream and all other malicious InputStream subclasses."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39139 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39139"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39140 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39140"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39141 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39141"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39144 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39144"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39145 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39145"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39146 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39146"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39147 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39147"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39148 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39148"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39149 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39149"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39150 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39150"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39151 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39151"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39152 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39152"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39153 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39153"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-39154 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-39154"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43859 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2021-43859"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-40151 affects version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2022-40151"
      },
      "action_statement": "Vulnerability CVE-2022-40151 affects version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41966 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2022-41966"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2",
          "identifiers": {
            "purl": "pkg:maven/com.thoughtworks.xstream/xstream-parent@1.4.17-tuxcare.2"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-47072 is fixed in version 1.4.17-tuxcare.2 of com.thoughtworks.xstream:xstream-parent.",
      "vulnerability": {
        "name": "CVE-2024-47072"
      }
    }
  ]
}
