{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:20912bf4-7755-5ce2-8a7a-86bb9770ac10",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.26.0-tuxcare.1",
      "type": "library",
      "name": "axios",
      "version": "0.26.0-tuxcare.1",
      "purl": "pkg:npm/axios@0.26.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:81c77de7-15c2-5ecf-97ee-89c2b3bc8fda",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d87b31-ed17-595d-b600-a30371f2ad42",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.26.0-tuxcare.1 of axios. not_affected \u2014 Axios 0.26.0 is NOT AFFECTED by CVE-2024-39338. The vulnerability requires the WHATWG URL API (new URL()) which treats protocol-relative URLs (//host) as valid URLs that resolve against a base. Version 0.26.0 uses the legacy Node.js url.parse() API, which does not resolve protocol-relative URLs to hostnames, breaking the SSRF attack chain. Tested behavior confirms that requests with protocol-re..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:094ff2d9-0850-5413-a3b8-998cf7338abc",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27152 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4360a986-e5ef-570e-8763-a484d1fa4bf8",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c5ef098-8772-53ca-ab96-6afed1e37891",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25639 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6af018a5-603d-58dc-8f09-e3b5300582f5",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:120103c3-6c58-514e-b101-46d038cfbcb2",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a84a3d-1621-5124-8072-2fabc11e87cf",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bac9b39-a5c9-5473-81f2-1a55921b90d0",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 0.26.0-tuxcare.1 of axios. not_affected \u2014 The target axios version 0.26.0 is not affected by CVE-2026-42035. The vulnerability requires two components that work together: (1) duck-type FormData detection that can be fooled by prototype pollution, and (2) code that calls getHeaders() on the data object and merges the result into request headers. Version 0.26.0 lacks both components. The http adapter does not contain the vulnerable code ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c4d9d1d-f65e-57a0-9cde-2073a2b46827",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42440d6b-c0a2-5493-b090-4234d11ba0c1",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d9ea90-2f08-56fc-88a5-db87123e1675",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42039 does not affect version 0.26.0-tuxcare.1 of axios. not_affected \u2014 The vulnerable buildFormData function exists in version 0.26.0 but is unreachable from axios's own production code. Unlike the affected versions (1.7.x) where toFormData is actively used for params serialization via AxiosURLSearchParams, version 0.26.0 uses a completely different architecture that does not invoke toFormData at all. The CVE's attack path 'axios({ data, params })' does not reach ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7a2f28f-550a-579a-9251-e324f77ec4dd",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42040 does not affect version 0.26.0-tuxcare.1 of axios. not_affected \u2014 Version 0.26.0 is not affected by CVE-2026-42040. The vulnerable file lib/helpers/AxiosURLSearchParams.js does not exist in this version. It was introduced on 2022-05-25 (commit 934f390c), three months after v0.26.0 was released on 2022-02-13. The target uses lib/helpers/buildURL.js for URL parameter encoding, which does not contain the problematic charMap entry that reverses null byte encoding..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945d4b0b-683f-597b-bbd2-4ba4789b4b30",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28eea1be-d46f-5a12-8cda-d4dd602988f2",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 0.26.0-tuxcare.1 of axios. not_affected \u2014 Version 0.26.0 is not affected by CVE-2026-42042. The vulnerable withXSRFToken configuration property does not exist in this version - it was introduced in later versions (1.x+). Version 0.26.0 uses an older XSRF token architecture based on withCredentials, which is handled in lib/adapters/xhr.js rather than the lib/helpers/resolveConfig.js file that contains the vulnerability in newer versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0979b02e-5acf-50b6-a3de-7398de4590fb",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1975ded2-b89c-561a-8305-0b3831f2344a",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96ca236f-e079-5ef9-a5ca-42e9b8683f5a",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:597ee0aa-c1d6-59a8-9af0-f47ba7d65510",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a32aaaa1-247a-5d68-9402-c333ba8996c4",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce77f932-3210-5450-b27c-480a0af86520",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a161ff-02ff-58c8-9ad6-9c8468403cd2",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a2d316f-977b-56be-89bf-70ef8e491e63",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7647845-c30d-5b88-8cdf-53dcd2a8b120",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.26.0-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.26.0-tuxcare.1"
    }
  ]
}