{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a917cf57-5a58-56fd-9c5c-7e8c57b09600",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@4.4.19-tuxcare.2",
      "type": "library",
      "name": "tar",
      "version": "4.4.19-tuxcare.2",
      "purl": "pkg:npm/tar@4.4.19-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:020bef35-3a2c-55d1-a3cc-8f160ee02987",
      "id": "CVE-2024-28863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28863 is fixed in version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4355dad0-82b0-5202-9c16-b98076b3bfaa",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-23745 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d20752-c756-5c71-b450-b47cf42d13b5",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-23950 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:102a9cc5-0486-59ac-b751-665f6088e21e",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24842 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adb0f425-f503-53e9-9f98-166ca1fb9968",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26960 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:325f3507-8988-5d55-90b7-6dde655a6721",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29786 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b83481f-6e7a-5895-b4f3-ec682bbe09de",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31802 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04a0d68e-a124-5db5-92b4-ce65e57b9084",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53655 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ab5f941-fc1c-59b0-8b43-7d1b595c5a9b",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59871 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d766d873-4cc8-5163-a3f3-99b03ead3bd9",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59873 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ffef3c7-bbf8-5a63-9340-903fd74fab95",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59874 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb2086f1-cb79-55bb-8e83-89ff9df026c7",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59875 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb4cf7a-4cc3-5eb3-b837-cbd1ec325e2e",
      "id": "GHSA-qffp-2rhf-9h96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qffp-2rhf-9h96 affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c484a8b-64f8-5655-8941-1e6f88119ca5",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r292-9mhp-454m affects version 4.4.19-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@4.4.19-tuxcare.2"
    }
  ]
}