{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b439b7f2-d50a-5cdc-9603-bf4796834e23",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nuxt@3.2.0-tuxcare.4",
      "type": "library",
      "name": "nuxt",
      "version": "3.2.0-tuxcare.4",
      "purl": "pkg:npm/nuxt@3.2.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:682468b8-3795-5132-ad29-42c9ee3de385",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53bfebc9-0efc-55cd-ae32-8d4735b6b46b",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29de5d90-657f-5a18-9dd0-96f4b18e6310",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae8d5286-b6c2-5e65-99d4-7692edef9a30",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dadcda58-6a7e-5c09-825a-336755c94e17",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f99b4d22-6274-5053-863f-89dab2f6418a",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c50f6116-30e1-51f4-8f55-44a68990fb8d",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6046f114-9d4d-57e9-9e44-922e7d2cbf35",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59f785e1-137b-5834-a4e4-ee9c11d74e1d",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ded5bf-b328-5537-b6e0-4af367eda96f",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99a694b-0a50-5fcf-98ff-91499774cce8",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:417502c7-7cf1-5068-8d7e-f9314d349294",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f27009f-ee54-5e94-bdf8-fcc7bb40d958",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eaf9b09-4c8c-5804-aeee-8f0878f52c0c",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fff8e6b-093c-5dce-9c4d-085b1873271b",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b71442b-73c9-52c3-aeec-6b050b9dbdb6",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e984d57-b72d-5a93-a6bf-79160d262616",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a1f9534-15db-57ff-8635-06d9c56ef5cc",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f28859b-2ba6-581a-866e-7c791844e61a",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43f17130-915f-5050-9c5a-ad09cbc050a3",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4288c06-e359-5649-b6e1-1dff0e7407ea",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57448213-e110-556b-8d9a-46cf29a1c598",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d69e3aa-dd8d-5652-b087-67e718b6c8fc",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77e5074a-6194-52fb-baff-a95150c5704b",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for nuxt 3.2.0-tuxcare.4. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5df282a3-24e9-5fbd-87ef-c170a91c3306",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802015f1-57ac-526d-95d8-ad9d0ba65d11",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c59431e4-f0be-5725-8a51-2a9edcaf15e6",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.4 of nuxt. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65719d91-e081-5c83-bc5c-4218d5bb0602",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29da59c0-e2e8-5a64-8f56-7641efc46a7d",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.4 of nuxt."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b00af81-4073-5d19-b032-650f52465aa3",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.4 of nuxt. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:376796f8-c933-57b0-99a5-af8d2805a744",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.4 of nuxt. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b607ce0-9d84-50c3-a1e3-1f1c02077ff3",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.4 of nuxt. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nuxt@3.2.0-tuxcare.4"
    }
  ]
}