{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9c4649ff-0844-58e4-a71e-f6d2f27807ff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.6.8-tuxcare.1",
      "type": "library",
      "name": "axios",
      "version": "1.6.8-tuxcare.1",
      "purl": "pkg:npm/axios@1.6.8-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c605f1ef-9c4e-5b5b-a36b-5d6636b0d0f1",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39338 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79a28c28-af20-5804-a75a-e832b7ce5ccd",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-27152 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2025-27152 fix already exists in commit 22c2e77ccde46e0a3c0d1513b682eba8dfb41d75"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0f75bac-ac29-5d95-8034-e2fe83a3c536",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-58754 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2025-58754 fix already exists in commit fe89d8c609e567fa731f7677ab065742330f25ea"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daeb328e-12bf-57ea-8fdd-e85d5482ef84",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2025-62718 fix already exists in commit dd333bdabf51d856d0d14fe7bd9d50ac817e4aa2"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9feaa5ee-b2bd-50e1-8646-8b0f3c7226c7",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-25639 fix already exists in commit f4e3c49872deb794ae9a7bb71a8345ea2ec4b6eb"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:268a0ae4-ddc2-54e5-b302-6143e07a598e",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40175 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-40175 fix already exists in commit e3c915c5421c511d667ffeace65d8d65829e19e8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4cb1cb2-dea6-566e-926d-5bf5ca01af15",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42033 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42033 fix already exists in commit 9c513d377d64d936e51eb33b901bb6a26258abd8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aa46cc8-ca8e-5271-a5c1-a81151ed173d",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42034 fix already exists in commit cd256b069536974eeec07e8047ceeb87986d19bc"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb286c17-2dd2-52fc-87f6-c5b15184ad1f",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42035 fix already exists in commit b9e4e1b49f5f62215e46c059f343b2e9ccb81c39"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a99aa7f-d162-5ae8-b7e8-62abb600c918",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42036 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42036 fix already exists in commit db7082ebbf0cf245e8d001407b789a154606afac"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb229ebc-bc5f-5f3b-ba6e-6bf4d194837f",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42037 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8539ccb8-65ea-59af-b0cc-c9949ac65565",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42038 fix already exists in commit 38fbaef2676858fc97ea981cf9e2fabf343e60a4"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543db8cd-dff5-55aa-9384-d821c9237ecb",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42039 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42039 fix already exists in commit da36cba07a133fa5f833556303db0e3e5ce3dc87"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5755f00e-7b05-55e3-b61b-52d5e419399b",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b54765-db9a-5cfb-af7a-106de69cbdad",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42041 fix already exists in commit 935b8c002f9b50ff36d4f0ed3b6be5fc855a0b6e"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeb974d2-a89e-5756-98a7-aed22dd95b03",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42042 fix already exists in commit be54ef4e740e14b267e765f8e42ff9104d78bc8b"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f96946e-b81e-575e-a59c-ae0ed739f28e",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.6.8-tuxcare.1 of axios. CVE-2026-42043 fix already exists in commit 2a6288f317a7bfc46a41088a3809a22e8193340a"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee280339-3f27-56e9-88e9-bc8f62d00be9",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42044 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0590d0d4-1f7e-59a0-9fbc-84451444a6cb",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42264 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5110ed3d-a0ac-50e3-ad65-d5b8580e9fc2",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3358bf04-53de-586e-abac-9f12b77e18e7",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29fb5285-d8b7-59d1-bb49-89b0fc094f1b",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac824f3a-2af0-5766-9852-c5cff104a621",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 1.6.8-tuxcare.1 of axios. not_affected \u2014 axios v1.6.8 is not affected by CVE-2026-44492. The vulnerable code (lib/helpers/shouldBypassProxy.js) was introduced in v1.15.0, and v1.6.8 predates this entirely. The target uses a different architecture (proxy-from-env only) that is outside the scope of this CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e866c20-3605-5d70-9f08-e75f8c16df7c",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44494 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edd8c780-4bb6-5b74-b613-9459385c308d",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a7e107b-7339-5e9a-904a-e952a8f6b726",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd0f7ea4-242c-5b28-9e1b-d3964529a84a",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98d9f9a-2d1e-5c11-a465-fec628cd9a9b",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e58a94a0-1995-5a60-9b61-52955e483920",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c5057d-6f18-5982-88f9-a2fcb7a2215c",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.6.8-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.6.8-tuxcare.1"
    }
  ]
}