{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:339eb2da-1576-5e4d-a896-76822e1461b3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.27.2-tuxcare.3",
      "type": "library",
      "name": "axios",
      "version": "0.27.2-tuxcare.3",
      "purl": "pkg:npm/axios@0.27.2-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b19e121e-d063-5098-9b23-b11733224b63",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83954be4-5e4c-5007-8ddc-e6f794f4f587",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.27.2-tuxcare.3 of axios. Version 0.27.2 is not vulnerable. Summary: The target repository (axios 0.27.2-tuxcare.1) is NOT vulnerable to CVE-2024-39338. It uses the legacy url.parse() API instead of the vulnerable new URL() constructor with hardcoded 'http://localhost' base. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dba88f9-1bea-5f65-8e61-110d541ca12f",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20c6ff21-38a6-58c2-bcda-bade5f82f297",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:877a1997-3bca-5a49-b080-8571b394a932",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2adcdee-0084-5a81-9486-fae0a4f9b79d",
      "id": "CVE-2026-39865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39865 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b93a128-aa3d-5e27-a016-25dba01705e2",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e1fbb69-30e4-5e94-bc1e-b451aed24510",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46c92766-a767-533a-bc80-1691691e53a0",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:affe8aab-0697-5b45-9438-054aca581998",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30a7e95-6cda-5732-a97b-c37d449916b4",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62ace29f-89cf-55b3-9d70-440efab618b9",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ca1e86d-8d16-59d9-bf64-b584a69bfe60",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42039 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:942a43bc-bd48-5281-8fae-3771aed0bf18",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b860ed57-cc7d-5f5e-b3dc-4d07d71a9735",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c607085-c83f-504a-a0de-231469a38dc1",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ac8ebf-03f1-5110-9b53-1dce75d82235",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e3a33f6-cf2b-5b96-a3f9-e25820147830",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17e05094-39b5-525d-a45d-dcd5a52b8051",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:797c803b-eeca-5f7c-b865-e72af0300abc",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3072ddcd-b3ba-5f8a-8973-553174a7a907",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3506b1e4-0ec5-514a-a063-45d34e463d51",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0be0d38-d39f-5dba-b687-83c2c4ec90b1",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:436c75b1-fbfb-5fbd-8d7e-63fa91854fce",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c584e1ab-25c9-5446-9907-7585ece9dd5a",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.27.2-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.27.2-tuxcare.3"
    }
  ]
}