{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4f834269-45fe-5a3d-afd4-5ae42e225c7d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/astro@2.10.15-tuxcare.6",
      "type": "library",
      "name": "astro",
      "version": "2.10.15-tuxcare.6",
      "purl": "pkg:npm/astro@2.10.15-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e7a1cc63-c1da-5f22-8fdd-70cd9ae8a6c8",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a388c5f7-015b-5479-9723-1e3ba65a069d",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d42ca549-a61f-536b-b236-94d479612efe",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:816efe1c-a641-5e38-8f28-5017eb8cc4ee",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:930c2a9b-7f47-56d0-be48-e6c4b350344f",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7927f2d7-d0fb-5ed3-8632-22781300b5ea",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd6e787-82bb-5da5-9e25-7654c964ccd2",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5b844a-f8eb-5723-a6a9-2ecd6f9393bd",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05ac241a-d6ab-553b-b96b-7786867c2064",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c87f361-8616-575b-a3ec-4c9b81f9bf52",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d1d6ec8-e32a-529f-acd7-279aba5f7926",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0cac6a-4cc6-5fc4-a0f3-1d688b44dbcc",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 2.10.15-tuxcare.6 of astro. not_affected \u2014 Astro version 2.10.14 is not affected by CVE-2026-45028. The server islands feature with encrypted parameter handling does not exist in this version. The vulnerability requires server islands (introduced in later versions) to be present, specifically the encryption/decryption of props and slots parameters via AES-GCM. Version 2.10.14 predates this feature entirely. While the repository contains..."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b8cf4ef-bf39-525b-8a1e-4cc74f6d0d06",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8fc55d-dcdb-54e3-8f53-dd41e908ecf6",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2595ef53-9007-54d3-866d-59d185aee758",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03455f65-879d-5f6c-9333-24d202d4c9cd",
      "id": "CVE-2026-59728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4844b5-c7b3-51f4-be78-b8d55c5f98b1",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f973b810-79bd-5ae2-9082-828510fb1fae",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa74157-6787-5189-9d55-d13157eb9961",
      "id": "CVE-2026-84376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d04694ca-e195-5538-9e1d-f5d56870b270",
      "id": "GHSA-26w7-cxv4-gfx2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f65b6414-29ba-5bb7-bce8-4ec23dd66798",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 2.10.15-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/astro@2.10.15-tuxcare.6"
    }
  ]
}