{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:acb47151-a82c-5620-96dc-22e6ea1078c8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "6.10.2-tuxcare.1",
      "purl": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2d0d4ec2-edd9-5418-a111-b092e5c26af7",
      "id": "CVE-2022-25878",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25878 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c384d4e8-0d1c-5e49-a74f-0519ea34757c",
      "id": "CVE-2023-36665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36665 is fixed in version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7f0ff17-31ad-50b4-8bfb-e199483a479a",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c788ba36-5d16-5c6e-a673-2449b8eb1d27",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44288 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4bf21e2-05ea-5db6-bc0e-278090c6b4fb",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44289 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d62698-d6e3-53de-bd8b-7027997ed887",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 6.10.2-tuxcare.1 of protobufjs. CVE-2026-44290 fix already exists in commit f87c65fb1bedc7be0ee2504542878b86ee943218"
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2df6f20-c40a-52cd-8a54-b2c3279720e2",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44291 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93bb68f9-6a4b-52aa-b2d5-1415bc1fde2d",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44292 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11e1b426-5c24-585b-98ad-e26a1aaa6c26",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44293 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89cb0af7-9ada-5479-b57e-abac591fe349",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44294 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba5d4d6-d163-572c-a2a2-0c68b750e0bb",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9ed2357-9105-5c96-ac04-9d9924754145",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:131cdf15-3af4-56e8-8144-2e0e2141a638",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.10.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3718ea03-c47d-56e5-b9b7-13267ed10902",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.10.2-tuxcare.1 of protobufjs. not_affected \u2014 Target version 6.10.2 is not affected by CVE-2026-54270. The vulnerability concerns excessive memory retention from unknown field preservation, a feature introduced in protobufjs 8.2.0. Version 6.10.2 does not implement unknown field preservation; unknown fields are simply skipped during decode without storing them in memory."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5417c1a8-6e2b-5809-8002-e5931fa626d9",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.10.2-tuxcare.1 of protobufjs. not_affected \u2014 CVE-2026-59876 specifically affects the optional Text Format extension (ext/textformat.js) which does not exist in protobufjs version 6.10.2. This extension was introduced as a new feature in version 8.x. Without the Text Format extension, the attack vector described in the CVE cannot be exploited."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9400fcae-7ea5-57f3-baeb-9073192223cc",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.10.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 6.10.2 is not affected by CVE-2026-59877. The vulnerable code pattern (a while loop advancing through tokens looking for '=' without EOF checking) does not exist in this version. Version 6.10.2 uses a different architecture with skip('=') that properly handles EOF by throwing an error."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.1"
    }
  ]
}