{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5c080f71-966f-5a3a-837b-8e633213d6b3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "lodash",
      "purl": "pkg:npm/lodash@4.11.1",
      "type": "library",
      "bom-ref": "pkg:npm/lodash@4.11.1",
      "version": "4.11.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2018-16487",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:b52e1db9-0f02-5d44-b502-91af7853a44e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-16487 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2018-3721",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:131a224f-35ba-5040-88c0-d6af06324d84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-3721 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2019-1010266",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:6e8c51e8-b917-5ecb-bafe-69ae269d9290",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-1010266 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2019-10744",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:db602aeb-424a-5564-a4b6-ee6b09d57335",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10744 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2020-28500",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:8c94dee9-2393-5a1b-98ae-de89309d54f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-28500 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2020-8203",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:95bb8db4-25e3-5c66-84de-c7cc74a55166",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-8203 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2021-23337",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:2ee8ef5c-c092-5c7d-aa6a-d66f80c76630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-23337 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2021-41720",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:3a3db513-c5c0-547e-b4dc-ac8da4114f52",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41720 is a false positive for lodash 4.11.1."
      }
    },
    {
      "id": "CVE-2025-13465",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:a8ec6567-3465-567c-9944-6747291ff67e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13465 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2026-2950",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:0cdb539e-45bb-5d7c-9774-0b16c252c598",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2950 affects version 4.11.1 of lodash."
      }
    },
    {
      "id": "CVE-2026-4800",
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.11.1"
        }
      ],
      "bom-ref": "urn:uuid:d5aadd15-236c-53e7-93e6-cf2379d67135",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 4.11.1 of lodash."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash@4.11.1"
    }
  ]
}