{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f0550167-6ecd-50cf-b55b-bdc256e8b5a5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@6.2.1-tuxcare.5",
      "type": "library",
      "name": "tar",
      "version": "6.2.1-tuxcare.5",
      "purl": "pkg:npm/tar@6.2.1-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0ffb4c96-a7d7-5db6-be71-0b0f28cfef5d",
      "id": "CVE-2024-45296",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45296 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d10764a-4408-5b83-bd57-aa1da76c1385",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e27da6c-e816-5b16-a348-a7b52cad43a2",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1259b8a-2658-5063-ab51-be10ed1c1f87",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45351d1-eee4-5456-bcdb-badc8d33a8f4",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf508bbc-b490-5f4e-b1b5-6bb94e28488d",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29786 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb4eea5-109c-5e0f-9f27-2ba5793da22f",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31802 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c44a933-bcfc-50bf-96d5-e2d75c121939",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53655 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93358b91-b423-5eb6-a4af-45a0c7dab1e0",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59871 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:107095dd-f092-5864-a4c7-39f090d94d54",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59873 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d8990e6-9411-56cc-9872-385c215ccf30",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59874 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f78ea38-5a42-5583-a579-6426c378af6c",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59875 is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdb6a8f1-44dd-5d95-8fd8-26eccf993757",
      "id": "GHSA-qffp-2rhf-9h96",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-qffp-2rhf-9h96 does not affect version 6.2.1-tuxcare.5 of tar. already_fixed \u2014 The target repository (tar 6.2.1-tuxcare.3) already contains a backport of the vendor fix for GHSA-qffp-2rhf-9h96. The fix was applied in commit 4b41989e on March 13, 2026, which backported CVE-2026-29786 (the CVE identifier corresponding to GHSA-qffp-2rhf-9h96). The defense strips drive-relative root prefixes (like 'C:') from paths BEFORE checking for parent directory traversal sequences ('..')."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8a6a21-950f-5862-abb9-a591020d590c",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-r292-9mhp-454m is fixed in version 6.2.1-tuxcare.5 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@6.2.1-tuxcare.5"
    }
  ]
}