{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d2ebe93d-a90b-5478-b7cc-ffe1f0e1574d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5",
      "type": "library",
      "name": "@nuxt/webpack-builder",
      "version": "3.2.0-tuxcare.5",
      "purl": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:81189d56-bc61-558a-bcca-0f715dcffba7",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd9ef57-75dc-50a2-b94e-9f4c217555b3",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6269afaa-bc4d-5736-8dd5-3fceff704330",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8320ce47-391b-5f66-98ab-388ccbe2bb9e",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5795399f-fd79-519c-857d-d4ad9d4728b0",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b666447d-b25d-5ee7-8c80-ab5ce1b2502c",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a22b9d37-c46f-526e-92c2-9c4c47e45fd5",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9f178e-e20d-54d9-a8f8-e83b5352b521",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd209332-f7e4-5246-8266-53d60edc7c20",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f18fd1-dd17-51b9-88f5-54ffad347bae",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d20a760a-8704-5391-9cf5-6f1e46101049",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:463fb0bd-36e7-58da-8ab2-69905eca4f3d",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d57bc27-85ff-519c-95b2-cce30b6eef3f",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc0c1b04-d414-514b-9e1c-e24f0c5a3dc8",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beef3fa4-d6ab-5c2c-b0cc-6d39b5b9b1a7",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.5. CVE-2022-25852 is a false positive for this repository. The CVE affects pg-native and libpq npm packages (PostgreSQL database client bindings), but this repository is the Nuxt.js web framework (version 3.2.0-tuxcare.4). Exhaustive containment search found no pg-native/libpq code in the repository - not as the project itself, not as a vendored/bundled copy, and not as a declared dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42b4e668-444c-5f70-a33a-321edfe509fb",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c3231b1-953b-5820-af90-fe78b7522f21",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34343 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a55b4513-f3f9-51e3-9e46-393aa1ee7015",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba85c1a-4c5b-5b7c-a37a-7ddc57401546",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103d72fd-15c4-529f-87f0-de19ed24fa61",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f1967c5-8af4-5487-bd9e-30e2cf8e1b89",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edfb1f2b-58f1-59f5-a5d8-8b7ef10b02db",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22786b14-ba25-5098-b7e8-fbb66778e2ae",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe0165a-d4c9-57d1-b1ef-6ddcbb69615e",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.5. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4bfb873-4ca3-5945-b0eb-7a56887d515c",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45669 does not affect version 3.2.0-tuxcare.5 of @nuxt/webpack-builder. not_affected - CVE-2026-45669 requires the SSR redirect body that navigateTo(url, {external:true}) builds in packages/nuxt/src/app/composables/router.ts (nuxtApp.ssrContext['~renderResponse'] with only the double quote percent-encoded). In nuxt 3.2.0 that code does not exist: the server-side external branch of navigateTo delegates to h3 sendRedirect(event, redirectLocation, code) and builds no HTML body. Grep over the branch: '%22' - 0 hits in source, 'renderResponse' - only packages/nuxt/src/core/runtime/nitro/renderer.ts. The sink appears in later majors: 4.0.3 has it and carries patches/CVE-2026-45669.patch."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b3130f-3337-59a7-86de-9d6a9b12ff5b",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde47fce-6d5e-5034-82d8-46f62051f414",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.5 of @nuxt/webpack-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fbc71c5-7872-5a8d-93fd-6c8d00951abc",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c32fe2ff-b839-571c-8cbf-7cb3b0034caa",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f617ec13-9f3a-535d-bcba-83dc76fe5f01",
      "id": "CVE-2026-56317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56317 is fixed in version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08af7d13-0434-51fa-82d2-3da3c7bb9815",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.5 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eccd86af-09bd-5fa1-8b11-1b49c9e0fd45",
      "id": "CVE-2026-71314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6ccc874-7afb-5bf8-8e69-dfe66af33ac6",
      "id": "CVE-2026-71316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 3.2.0-tuxcare.5 of @nuxt/webpack-builder. Nuxt.js version 3.2.0 is not affected by CVE-2026-71316. The vulnerability requires runtime payload caching (introduced in Nuxt 4.x) where _payload.json entries are served before route middleware. Version 3.2.0 only has build-time prerender cache (null during runtime), uses _payload.js files (not .json), and all runtime payload requests undergo full SSR rendering with route rules enforcement. The vulnerable code path (runtime cache bypass) does not exist in this version's architecture."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:328414b0-1335-591c-bada-114009ec9da3",
      "id": "CVE-2026-71318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca13863d-9b4d-5ee5-8596-792bac46c559",
      "id": "CVE-2026-71321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 3.2.0-tuxcare.5 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:481c83fd-8b5d-5308-ae8e-4d46021fcac3",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.5 of @nuxt/webpack-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be3c9369-d198-59ca-bc9b-fc732e8855ad",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.5 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ce1f054-034d-5c99-b528-5253f51d2d85",
      "id": "GHSA-xppm-jmw6-fhmf",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-xppm-jmw6-fhmf is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.5"
    }
  ]
}