{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a700e63f-582f-5716-af2b-09302ae123bb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.21.4-tuxcare.1",
      "type": "library",
      "name": "axios",
      "version": "0.21.4-tuxcare.1",
      "purl": "pkg:npm/axios@0.21.4-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4b8e5c79-34f7-58dc-8d58-ad6ada2be75a",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72e556a-9f47-5e8d-9dce-8dd38e675a02",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.21.4-tuxcare.1 of axios. not_affected \u2014 The target repository (axios 0.21.4-tuxcare.1) is not affected by CVE-2024-39338. While the upstream vulnerability exists in axios 1.7.2 which uses the modern WHATWG URL API (new URL()), version 0.21.4 uses the legacy Node.js url.parse() API. This architectural difference prevents the SSRF exploitation: url.parse() treats protocol-relative URLs (starting with '//') as pathnames with null hostna..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b6dc6d-840c-5454-8199-f1e949146ac6",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ddab428-6409-56d4-bf18-a168bd6a8ca5",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196f3095-11ee-5dea-b72e-35dfc6359c07",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce788b8-b167-5965-b74e-4553c4f64679",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15fd1d39-2ead-5f0c-9764-1731570f71cc",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b445380-48e3-501b-ac7f-b06efd1e4b34",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98e13472-e49a-5a60-a5ea-29fdc79bc300",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed497ff-a565-5053-a787-bdf61ad9dc18",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d34503-4467-5431-bab2-461ba9a1af59",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4cdadd3-d61a-5278-b53a-663cc9d615b8",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e0f3a7d-72a9-5b53-9187-40ba5f33d800",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ffbc9be-859f-53a2-82bf-bdb5f9769ee3",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c98b9b35-e841-5042-82fc-815434d76c28",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:059f3634-c88a-5080-8f71-019d0aff5c5e",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42043 is fixed in version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edbcaf7e-0b9d-53a5-9776-f7678fb85ecf",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d463a6d4-d168-5b62-96ba-c5fe995079af",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28387d75-af8c-5d89-81e1-ce048bd97e3e",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75df852b-d77d-5e22-8512-d12ef588b638",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b72b2fbf-df14-5632-a588-cf7c446259b5",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44495 does not affect version 0.21.4-tuxcare.1 of axios. already_fixed \u2014 The target repository (axios 0.21.4-tuxcare.1) already contains the fix for CVE-2026-44495. The vulnerability was addressed in a prior TuxCare backport under CVE-2026-42033 (commit cb446abd, July 1, 2026), which implements the same hasOwnProperty guards as the upstream patches."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:147898d1-0c54-5340-8d2a-55528a74ba1b",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67beedd1-8738-53af-a9dc-e6dd2b0a3d58",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0964b2a4-9436-502d-8138-d449cbe45e08",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.21.4-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.21.4-tuxcare.1"
    }
  ]
}