{
  "schema_version": "1.6.0",
  "modified": "not-a-timestamp",
  "published": "2026-01-05T00:00:00Z",
  "aliases": [
    "SAMPLE-CVE-2026-0002"
  ],
  "summary": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library.",
  "details": "SAMPLE advisory: fabricated unsafe-deserialisation issue in a fictional cache library. This record exists only as a test fixture; the package, the advisory and the identifier are all invented.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "example-cache",
        "purl": "pkg:npm/example-cache@0.9.2"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "fixed": "0.9.5"
            }
          ]
        }
      ],
      "versions": [
        "0.9.2"
      ],
      "database_specific": {
        "source": "NOVUS-SAMPLE",
        "cwe": "CWE-502",
        "vulnerable_range": ">=0.9.0 <0.9.5"
      }
    }
  ],
  "severity": [
    {
      "type": "CVSS_V3",
      "score": 9.3
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.orchard.example/NOVUS-SAMPLE-2026-0002"
    },
    {
      "type": "FIX",
      "url": "https://git.orchard.example/cache/0.9.5"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "cvss_score": 9.3,
    "note": "Advisory identifiers use the invented NOVUS-SAMPLE namespace with SAMPLE-CVE aliases; no identifier here refers to a published CVE, GHSA or OSV record, and no package named exists."
  }
}
