{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:78448ab6-5d1d-52b7-a4ef-15b0a83b689c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40auth/core@0.37.2",
      "type": "library",
      "name": "@auth/core",
      "version": "0.37.2",
      "purl": "pkg:npm/%40auth/core@0.37.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1eb556ce-5d8f-5d39-96e9-0b3736c94a3e",
      "id": "CVE-2026-73418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73418 affects version 0.37.2 of @auth/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40auth/core@0.37.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a7bb563-9759-569e-a0b0-8e228581404e",
      "id": "CVE-2026-73419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73419 affects version 0.37.2 of @auth/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40auth/core@0.37.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45ce0e1d-d1b7-5b82-8dd5-95e791cb1c2d",
      "id": "CVE-2026-73420",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73420 affects version 0.37.2 of @auth/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40auth/core@0.37.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd7619cc-6440-57e2-9a52-0e0b0b66b9b8",
      "id": "GHSA-7rqj-j65f-68wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rqj-j65f-68wh affects version 0.37.2 of @auth/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40auth/core@0.37.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a195275-2778-54eb-b512-c902ff872ac5",
      "id": "GHSA-x445-f3h2-j279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x445-f3h2-j279 affects version 0.37.2 of @auth/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40auth/core@0.37.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d1d65b0-4f71-5e03-b999-fad0838d1bf3",
      "id": "GHSA-xmf8-cvqr-rfgj",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xmf8-cvqr-rfgj affects version 0.37.2 of @auth/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40auth/core@0.37.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40auth/core@0.37.2"
    }
  ]
}