{"@context":"https://openvex.dev/ns/v0.2.0","@id":"pkg:github/datadog/datadog-serverless-functions@aws-dd-forwarder-5.4.1","author":"security@datadoghq.com","author_role":"Vulnerability Management","last_updated":"2026-08-25T12:33:21.36212606Z","statements":[{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510138Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510138Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510138Z","vulnerability":{"name":"CVE-2026-1526"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510177Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510177Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510177Z","vulnerability":{"name":"CVE-2026-2229"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510247Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510247Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510247Z","vulnerability":{"name":"CVE-2026-12151"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510328Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510328Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510328Z","vulnerability":{"name":"CVE-2026-1525"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510363Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510363Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510362Z","vulnerability":{"name":"CVE-2026-22036"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510624Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510624Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510624Z","vulnerability":{"name":"CVE-2026-9679"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.51067Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.51067Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.51067Z","vulnerability":{"name":"CVE-2026-1527"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510707Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510707Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510707Z","vulnerability":{"name":"CVE-2026-16729"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510756Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510756Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510756Z","vulnerability":{"name":"CVE-2026-15157"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510861Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510861Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510861Z","vulnerability":{"name":"CVE-2026-16728"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.51095Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.51095Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.51095Z","vulnerability":{"name":"CVE-2026-11525"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.510997Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.510997Z","products":[{"@id":"pkg:npm/undici@5.29.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.510997Z","vulnerability":{"name":"CVE-2026-6733"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.51103Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.51103Z","products":[{"@id":"pkg:npm/activity_logs_monitoring@1.0.0"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.51103Z","vulnerability":{"name":"GHSA-p57g-c9gq-6vxp"}},{"action_statement":"","action_statement_timestamp":"2026-08-25T11:14:01.511053Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:14:01.511053Z","products":[{"@id":"pkg:npm/datadog-eventhub-forwarder@2.1.1"}],"status":"under_investigation","timestamp":"2026-08-25T11:14:01.511053Z","vulnerability":{"name":"MAL-2025-48623"}},{"action_statement":"This vulnerability was fixed in: 5.4.11","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T12:12:04.027468Z","products":[{"@id":"pkg:pypi/ddtrace@3.19.5"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510226Z","vulnerability":{"name":"CVE-2026-50271"}},{"action_statement":"This vulnerability was fixed in: 5.4.11","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T12:12:04.027449Z","products":[{"@id":"pkg:pypi/requests@2.22.0"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510103Z","vulnerability":{"name":"CVE-2023-32681"}},{"action_statement":"This vulnerability was fixed in: 5.4.11","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T12:12:04.027475Z","products":[{"@id":"pkg:pypi/requests@2.22.0"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510302Z","vulnerability":{"name":"CVE-2024-47081"}},{"action_statement":"This vulnerability was fixed in: 5.4.11","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T12:12:04.027478Z","products":[{"@id":"pkg:pypi/setuptools@80.10.2"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510531Z","vulnerability":{"name":"CVE-2026-59890"}},{"action_statement":"This vulnerability was fixed in: 5.4.11","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T12:12:04.027483Z","products":[{"@id":"pkg:pypi/requests@2.22.0"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510593Z","vulnerability":{"name":"CVE-2024-35195"}},{"action_statement":"This vulnerability was fixed in: 5.4.11","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T12:12:04.027488Z","products":[{"@id":"pkg:pypi/requests@2.22.0"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510923Z","vulnerability":{"name":"CVE-2026-25645"}},{"action_statement":"This vulnerability was fixed in: 5.4.6","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:45:23.129249Z","products":[{"@id":"pkg:pypi/ujson@5.12.1"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510563Z","vulnerability":{"name":"CVE-2026-54911"}},{"action_statement":"This vulnerability was fixed in: 5.4.4","action_statement_timestamp":"0001-01-01T00:00:00Z","impact_statement":"","justification":"","last_updated":"2026-08-25T11:32:47.398749Z","products":[{"@id":"pkg:pypi/idna@3.7"}],"status":"affected","timestamp":"2026-08-25T11:14:01.510502Z","vulnerability":{"name":"CVE-2026-45409"}}],"timestamp":"2026-08-18T12:22:22.823226842Z","tooling":"","version":6}