{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4e5a5e6b-a329-57e0-97d4-8b62e6784ac0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1",
      "type": "library",
      "name": "@nuxt/vite-builder",
      "version": "3.2.0-tuxcare.1",
      "purl": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:34090cdc-ba3e-53ba-b63f-aaeaa6f2c796",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06c33222-7e2b-5ae1-a725-9f54d25bdbd0",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606cb9c7-3f5b-5a60-9477-f4690b66bdff",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd30f001-7c8e-5a06-8c18-c031463b80cb",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1da1938-280c-5a6a-bb93-209dc75098c2",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86091105-2d2a-5fd9-bc01-f2499d1a2cde",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:221ef10e-7c05-50eb-8e67-d9fb7f4a2137",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f20631af-bdb3-53a5-95e7-37a14348f892",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6845393-76f2-5c0a-88a1-ed2600384679",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1398bf60-518b-5d30-b2f6-0f5bba0fe1d4",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d3c601-7ab2-51fd-8adb-e7a7c3f3d1af",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7382f741-6842-5f88-8bf7-1975fb88f3a6",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-8203 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:876ca5dd-0511-5ff1-9441-74a1fa17225a",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1da59a6b-5e95-57c9-83a0-80064ae8c410",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:930b2597-066b-5379-8cf1-5403a312c6f5",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c534f797-fb92-5138-bd84-6a50b02691f9",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e14095d-94e6-5d5a-88ff-90a51bf7e25a",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d97367-c7e7-5f9e-8e91-2c257c6d4e03",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31a4af45-a775-5ab7-a581-7eda2883c03b",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41aa1c6a-f904-5cda-bcba-81690101a589",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05867743-eb22-5457-a9bc-a2552ff37272",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cbdf7db-95aa-5625-b2d8-ffec59828ca6",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33151 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fb29a88-f150-5122-94ec-6630b43812e9",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ef467a9-790a-5a5f-82c1-e5701df419be",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.1. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc8f4c5a-93b6-5c06-9775-0c8a913fc59d",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2fd9159-8651-5644-b8b2-76832f810aee",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f78f22-7f02-50db-bf74-77845b9abc86",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db9538b4-63a0-5e6f-8455-96cede3ae241",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2760aa5f-9283-5763-9d7d-895838040bba",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21fad708-6032-5607-b508-deb80b2fd56f",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33cb0087-eb77-5b97-b550-8c77b21df372",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32045473-1281-5757-8753-87960bcbf9b7",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
    }
  ]
}