{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2db637fc-c463-5e0d-8555-9298c434e664",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.21.1-tuxcare.1",
      "type": "library",
      "name": "axios",
      "version": "0.21.1-tuxcare.1",
      "purl": "pkg:npm/axios@0.21.1-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8c704bf9-8e0b-5020-a6f0-6ffcaa147646",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6767614-3d06-5bff-9bd0-578cb4930e7a",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:099bf6c9-1572-5fdf-b871-ce274fa83fd4",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.21.1-tuxcare.1 of axios. already_fixed \u2014 The target axios 0.21.1-tuxcare.1 already contains equivalent defense logic against CVE-2024-39338 (protocol-relative URL SSRF) through the 'allowAbsoluteUrls' parameter added in CVE-2025-27152 backport (commit bc6d5a0b). When set to false, this parameter forces baseURL concatenation for protocol-relative URLs, preventing SSRF. The defense code exists in the codebase and is reachable on all exe..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdee709-f64e-54c6-b273-fbc3fe5936e6",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb896b72-e052-5200-b92c-01f9dab2302d",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0da3827-5bc1-513e-a8df-f7212fc9651b",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b392d5bc-4cbe-565d-adba-6d5bfa073110",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6b2b80-e35c-5fe0-baa5-06d3fce2df29",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07824953-6b82-5cd0-9638-e720641c686c",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c88d4c-99e9-5520-9606-10e6209b33e1",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c05493-32be-5c83-a6ee-c3eaf1a26e2c",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20d6c2ee-e1fd-53ae-b835-fb614e73dfc5",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b26b114-e16f-5257-9e41-637a71d3b6a1",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b21f8b27-fd0b-5082-aa00-b49cf6df8868",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bdd063a-7168-5240-b439-fa63863dffa2",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eecb6160-9d7e-532b-a45d-e17e4aee2a89",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d345c77c-9149-5b90-a9ba-5fff5d82d895",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42043 is fixed in version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31603241-fd50-544a-a222-8a703c257541",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7791bed2-6d83-50c5-ad2d-ce6399586453",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c37542-cc94-5f34-be0c-5212b4146eb8",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71990704-8fd5-5e2f-bb22-7a1528a40ac4",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87728b9b-a418-5ce7-a017-f46376ce460b",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddf7501d-d3ad-5313-a108-00e3f1567b4c",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d3bb465-a63e-5f88-8b6f-4dce95268df8",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f768cc1d-2806-5baf-8fc8-aeb20153e43e",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.21.1-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.21.1-tuxcare.1"
    }
  ]
}