{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d28c2256-ac07-5a43-99e9-0a6b96b6a7a4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/astro@4.16.19-tuxcare.2",
      "type": "library",
      "name": "astro",
      "version": "4.16.19-tuxcare.2",
      "purl": "pkg:npm/astro@4.16.19-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3c33d50c-d85c-5444-941b-40f6ff284c40",
      "id": "AIKIDO-2025-10879",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10879 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe35f9d-67ad-5b5c-890e-14e746894a85",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55303 affects version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a8cb4f-1598-51b0-b11a-fe15afe46594",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5188ae-d3a9-5144-87b1-3cf50b12b326",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec55c21-7668-53ae-a80a-44c70431a6ea",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec47b47-6f52-59ac-a410-db14a7b20738",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:106f55c8-0e93-5fa4-be57-598b0fd7a257",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b0e932-46b9-59d7-b030-cde9196b9df2",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef676974-446b-5def-b489-d8a1bc21a37b",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66ce40b9-58cf-5262-9734-531552de9972",
      "id": "CVE-2026-33490",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33490 is a false positive for astro 4.16.19-tuxcare.2. false_positive \u2014 CVE-2026-33490 concerns H3 (a minimal HTTP framework), but the target repository is Astro (a website build tool). H3 is not present in this repository - no vendored code, no dependency, no imports. The only 'h3' references found are HTML heading components (<h3> tags), unrelated to the H3 framework."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ed2a64a-baf5-5915-ae8f-c82a08e92baf",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba55ab4-2179-5b87-b3dd-33cfa01710f0",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794e3521-fce5-5ba5-ad63-cce753536ddb",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45028 affects version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc695888-075b-5893-be47-a1e75555edfa",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0efa76ce-51a0-5c16-81ad-7d18afb4a33b",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adc32ee8-65ae-524f-a182-8629cf5a870e",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 4.16.19-tuxcare.2 of astro. already_fixed \u2014 The target repository has already fixed this vulnerability via CVE-2026-25545 / AIKIDO-2025-10879 (May 7, 2026), which addresses the identical SSRF issue. The fix removes the prerendered error page fetching feature entirely, replacing it with direct SSR rendering. This is a more aggressive mitigation than the upstream's host validation approach."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b65c7149-2a60-5ea0-a351-1862a6c35844",
      "id": "CVE-2026-59727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59727 affects version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e343310d-2c45-5db1-b939-941173b4ccc4",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfa04652-a0ec-5bc8-8391-2760ae7fc9bb",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 4.16.19-tuxcare.2 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/astro@4.16.19-tuxcare.2"
    }
  ]
}