{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f83d89e3-a11c-549e-a045-0be679e08710",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4",
      "type": "library",
      "name": "@nuxt/kit",
      "version": "3.2.0-tuxcare.4",
      "purl": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cf0168b7-dfd4-5dc8-b41f-6742e88b68f8",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56a96c2e-680f-5dc9-81ef-a8a1f2c8b780",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38620d64-6501-51b1-8445-3606b2e85f0d",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab0109c5-e2d9-5027-afe4-224ed4362693",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e539885-d050-5136-9825-e6d33bdaf106",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88439f8d-4745-5e6a-be12-2b0f91e2b35d",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a88bf7e-67d3-53dd-9282-24aa14d5b04a",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e54ca3d8-fe05-5ac8-9b04-7091ad4cfa14",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a410fd-f64b-58cb-afba-33925ae7ed7f",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:681a9b1c-e8b3-5ce5-b1ec-af7199eb316d",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2c05ff0-2577-5c6f-aca7-058e8811a803",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ec6c7d4-4f1c-5645-a326-69c425674945",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59bf9280-311d-517b-b3bd-66130f5d8fbd",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7477fe4-e978-529e-8902-710ef6c34e59",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36f213a0-98cf-53e3-8799-120bc49e4dbd",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f07dbf40-7aa8-5fa0-863a-390289bed8b5",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d10178b-91f8-511d-8780-d1173ed50859",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5be0bbc5-2f98-5708-b6ee-028ae2a04077",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30528a8-c08c-5616-a47f-f15b669ae026",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e35adea-f055-599a-876f-b37a740aaf0f",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69b2e80e-fb0b-560d-a297-a148cb5036b7",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba4bdb6f-26c3-52ce-be9b-7da68cedcf34",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c6e073c-e624-5ae6-86f5-d8268af70f23",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257c1be5-5811-5b17-8445-90df384c4f09",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/kit 3.2.0-tuxcare.4. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c590309f-25e3-5604-aa76-5c4fec65615e",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83a3ef58-84c7-5a9a-9a4b-3818aa13326b",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe1f5b9-1abf-5b32-8fa8-173baac31c43",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.4 of @nuxt/kit. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e4b5153-01bc-5f7b-ae8d-09624ef5d793",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9db2af00-a62f-5ebc-a576-0be565d02692",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.4 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696fc98c-5c0e-5223-93a3-338e0983a251",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.4 of @nuxt/kit. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0930421-f0b8-5c98-8ea2-9206e579d07e",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.4 of @nuxt/kit. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea32e8d3-2de8-5352-96e3-2c0bfcbdee20",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.4 of @nuxt/kit. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.4"
    }
  ]
}