{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1042a05f-13cd-5d48-9da5-7ef8f2dc8bfd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.6.8-tuxcare.2",
      "type": "library",
      "name": "axios",
      "version": "1.6.8-tuxcare.2",
      "purl": "pkg:npm/axios@1.6.8-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:914a26f3-8948-5c28-9385-9e1b1c38e891",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39338 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6ad0346-347e-59b3-a637-bdea25ae52bb",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-27152 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2025-27152 fix already exists in commit 22c2e77ccde46e0a3c0d1513b682eba8dfb41d75"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:476747ab-b65f-573a-b8c2-488a4fb13901",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-58754 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2025-58754 fix already exists in commit fe89d8c609e567fa731f7677ab065742330f25ea"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4233520e-5082-5ff4-9ff3-7452eb27081a",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2025-62718 fix already exists in commit dd333bdabf51d856d0d14fe7bd9d50ac817e4aa2"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:288f5bcc-70e3-5869-8bbc-a1eafe8957de",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-25639 fix already exists in commit f4e3c49872deb794ae9a7bb71a8345ea2ec4b6eb"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64de29df-9f27-5fdb-92f2-c850031e7285",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40175 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-40175 fix already exists in commit e3c915c5421c511d667ffeace65d8d65829e19e8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eed6283-1f4c-557a-9cdd-0199328af777",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42033 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42033 fix already exists in commit 9c513d377d64d936e51eb33b901bb6a26258abd8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a22da07-1f12-5eba-acff-0aaac6f6d0db",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42034 fix already exists in commit cd256b069536974eeec07e8047ceeb87986d19bc"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ace193-dc56-5da9-80bf-39b266d312d2",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42035 fix already exists in commit b9e4e1b49f5f62215e46c059f343b2e9ccb81c39"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c84d0eb3-c580-54b5-85ba-41c88f1c48f4",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42036 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42036 fix already exists in commit db7082ebbf0cf245e8d001407b789a154606afac"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dabff31a-bfac-51af-8ede-68ed86e77bdf",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b481df0b-1039-58d3-87fb-4d6e5a85342d",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42038 fix already exists in commit 38fbaef2676858fc97ea981cf9e2fabf343e60a4"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd944c0b-a073-522d-b920-c09e4473cd6d",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42039 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42039 fix already exists in commit da36cba07a133fa5f833556303db0e3e5ce3dc87"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4effb9-6fa2-50e3-a1ce-635b4ef64add",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c1276b-a5c7-5319-9634-26f08736cd87",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42041 fix already exists in commit 935b8c002f9b50ff36d4f0ed3b6be5fc855a0b6e"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aaba9c3-d7d8-5965-b738-fa8858107cf1",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42042 fix already exists in commit be54ef4e740e14b267e765f8e42ff9104d78bc8b"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:301a6765-3942-5cb6-8d2c-296a400c4ccc",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.6.8-tuxcare.2 of axios. CVE-2026-42043 fix already exists in commit 2a6288f317a7bfc46a41088a3809a22e8193340a"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:052f4849-c1a3-5793-86f8-2023239321ee",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69d23655-0a6c-52b9-9327-9b2317f5ef55",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdaa16b1-9a1a-593a-bc17-17fce8aa0279",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68dd5895-7ef4-5599-a649-05e33c300239",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a644e41e-70d5-5869-bc05-cc7a3ba9f548",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae68e4b0-101f-5076-9f26-8453d2ee676c",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 1.6.8-tuxcare.2 of axios. not_affected \u2014 axios v1.6.8 is not affected by CVE-2026-44492. The vulnerable code (lib/helpers/shouldBypassProxy.js) was introduced in v1.15.0, and v1.6.8 predates this entirely. The target uses a different architecture (proxy-from-env only) that is outside the scope of this CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f242e00e-69dc-565c-8be8-76f5485a187e",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44494 affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d347a679-f4bf-559c-856a-1ccfcd04ac77",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cbb4de1-19f9-5847-b7a5-021b9a2cc7a3",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:099df492-6c0a-5aed-bd7e-ccfaa407bc80",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c217e239-d998-5edb-bba6-1482586b70af",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fd12b1f-f532-575b-a033-01b1e023b0c1",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45183d83-dad1-567b-9418-60380ce1aac9",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.6.8-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.6.8-tuxcare.2"
    }
  ]
}