{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7606df04-79dd-5bd3-8cb7-4ef531f85f53",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nuxi@3.2.0-tuxcare.4",
      "type": "library",
      "name": "nuxi",
      "version": "3.2.0-tuxcare.4",
      "purl": "pkg:npm/nuxi@3.2.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0b4f47f8-dbd1-5a7a-bb26-f0d509a23dbf",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ebc2ee2-9ac8-5fdc-a659-21b7988ba204",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a818c516-8ea0-5c5b-b800-4744bb2fa8c1",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4cccd8b-4028-5a59-94b9-d1e06e265af7",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbc4d881-b975-551c-b6fa-eba52c5e239d",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c9b484f-3016-5ca1-b9b4-3075d8832fec",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d189e2-ba0e-518c-a05b-ad844307da89",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fba8cc-37da-5d6b-98b3-5db764372c50",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54dd4bf6-b9c0-57d7-b007-1c81801c4515",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f62cfe61-d353-50e7-8d68-60d69987bd84",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196853a8-8c4b-54a3-bf6d-16e18002390b",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46dc6787-51e7-514f-9367-9a0824603bfe",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba5493e-f079-5351-8998-ed0fe6bfc7b6",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c248d40-f766-5857-a3e3-1d9f3a1a6b0c",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f64d02d0-a3c8-520a-ba3d-804f4b85ff51",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7ce8273-8871-5478-bc80-6b53e7787797",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a04a80-0a6d-55d8-83e5-b5af516c83c0",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:577749f1-1d82-5882-bd3a-3129068bf569",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b38faf16-3602-529f-899c-0f7e156f1948",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf4f5897-65f6-5a56-b684-b796aeba572a",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d334577c-52df-5b3a-9390-78c9084f6cef",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3d45d01-cd09-509c-abad-54f0d82a554d",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b87946a6-9002-5949-bf1b-8caef4025303",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa11102-1b25-58fc-bbac-13a52e3a86a2",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for nuxi 3.2.0-tuxcare.4. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ef764e8-1d15-5b5e-8158-ceb3a91df6ed",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad2f786-5f85-5900-b0d9-4a362261cc16",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3447605d-5f1c-5f7e-8b69-6a5b706e6e65",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.4 of nuxi. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ea2dd4a-4ce5-5282-89f5-eb2ef464c161",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35db33b6-8a2d-5b31-899f-01c8fb0c7403",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.4 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c070cc3-9435-5dba-9a82-b37d67b5db65",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.4 of nuxi. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20118324-7c87-56fe-921c-a596fc8f028a",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.4 of nuxi. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:147fe9dc-a8bf-5a11-9a84-84d4eeff70e3",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.4 of nuxi. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nuxi@3.2.0-tuxcare.4"
    }
  ]
}