{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b1fddd05-1237-5b2a-9609-1ce413a8b7fb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/astro@3.6.5-tuxcare.6",
      "type": "library",
      "name": "astro",
      "version": "3.6.5-tuxcare.6",
      "purl": "pkg:npm/astro@3.6.5-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0cbe7f54-28a8-593d-bed4-c16b4bceb210",
      "id": "CVE-2024-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47570655-3c34-5c2d-a205-913b834a3c7d",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c900c445-bb24-5b8f-96dc-b1d5ba35e89b",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5700eac-21c3-56f6-afec-f12e7fd67976",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6902b3c3-2e97-5d76-9e15-14c34e72eab1",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5c730a-d488-53a2-9d96-070c297ad90f",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c3bc0a6-fcd9-56ed-890f-6f1f814374c4",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be33c2b2-228f-5401-9d45-8188d780608a",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5152730-f86b-588b-9cc1-c545deef2f10",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05d3c914-c1ea-5f1e-96a3-d4eca0e4e9a3",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3462a52b-8d5a-57ea-ba64-7676df581be9",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0df1fa4f-14e6-59c9-88a5-850c8aa50484",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7e7fce9-1392-5cbf-8370-14af8b649f6b",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d5b33af-7791-597e-bdac-078149c5f74a",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.6 of astro. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con..."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a563097-8783-58a7-b698-409698f5205b",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fca4cde-7221-5a3f-bcaf-83668cf85c62",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2314353-0bee-5eb1-9af5-ae5ac024412a",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c54c90-b20b-506e-857f-5bc77d3adc5a",
      "id": "CVE-2026-59728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeebb05e-8ce6-5fe7-8631-2165df14e258",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b0632de-c2b1-5057-a99b-b3d63ee17f48",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4b0a17-f1b7-5623-b3b8-bec172263b33",
      "id": "CVE-2026-84376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0598b42d-651a-5a55-9fa9-fd51d1c2d423",
      "id": "GHSA-26w7-cxv4-gfx2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aad5ba8-d2f6-571a-a983-61b815a8bea9",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 3.6.5-tuxcare.6 of astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/astro@3.6.5-tuxcare.6"
    }
  ]
}