{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0f11b0e2-71e0-5b05-a430-e216e23acda4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/lodash@4.17.19-tuxcare.1",
      "type": "library",
      "name": "lodash",
      "version": "4.17.19-tuxcare.1",
      "purl": "pkg:npm/lodash@4.17.19-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:35016017-edf9-554b-ad91-6a822350b6ef",
      "id": "CVE-2020-28500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-28500 affects version 4.17.19-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a74f3a0-0a61-5878-be58-24417f10a42d",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-8203 does not affect version 4.17.19-tuxcare.1 of lodash. already_fixed \u2014 CVE-2020-8203 (Prototype Pollution in lodash) has already been fixed in the target repository. The upstream fix commit c84fe82760fb2d3e03a63379b297a1cc1a2fce12 is an ancestor of the target SHA 66b6c2c5d5935b3a01329e9598d8f8c97f5fb9e5. The defense code that blocks '__proto__', 'constructor', and 'prototype' property assignments is present in the baseSet function at lines 3993-3995 of lodash.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ecf75b4-12fb-5fa5-8976-80131f428f7f",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-23337 affects version 4.17.19-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e9e0fe5-0337-54b6-b9a0-514d7d20fcc3",
      "id": "CVE-2021-41720",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41720 is a false positive for lodash 4.17.19-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6265599-629a-5317-af3b-fda960ab4336",
      "id": "CVE-2025-13465",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13465 affects version 4.17.19-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a323e6-3c44-5c5e-8ee4-fd8c2c1876ac",
      "id": "CVE-2026-2950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2950 affects version 4.17.19-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e95d54f-655d-5aac-b8b4-6ceb2bd564b1",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 4.17.19-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash@4.17.19-tuxcare.1"
    }
  ]
}