{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e03faa6b-d623-504b-bd46-ad15a87b6f61",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.6.8-tuxcare.3",
      "type": "library",
      "name": "axios",
      "version": "1.6.8-tuxcare.3",
      "purl": "pkg:npm/axios@1.6.8-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:658b2bc7-9fde-52c6-8fe8-7541d9d29d4f",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39338 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6425d45b-c344-5254-a3f8-6a58ca622004",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-27152 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2025-27152 fix already exists in commit 22c2e77ccde46e0a3c0d1513b682eba8dfb41d75"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e4bc66f-8b85-5c8f-9278-1c9bba8896ad",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-58754 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2025-58754 fix already exists in commit fe89d8c609e567fa731f7677ab065742330f25ea"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0307a85-61a9-5600-a348-aafedb0eab77",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2025-62718 fix already exists in commit dd333bdabf51d856d0d14fe7bd9d50ac817e4aa2"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2354d26c-bf52-597c-90c4-7547db3cbcc8",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-25639 fix already exists in commit f4e3c49872deb794ae9a7bb71a8345ea2ec4b6eb"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:638687b9-cdbb-5481-b0f2-b435e6aa08c8",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40175 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-40175 fix already exists in commit e3c915c5421c511d667ffeace65d8d65829e19e8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:342d1a62-558b-51c1-b118-e5eb107f7c05",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42033 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42033 fix already exists in commit 9c513d377d64d936e51eb33b901bb6a26258abd8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a68be4-c5a2-55c9-8e28-1f1a156c7ab0",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42034 fix already exists in commit cd256b069536974eeec07e8047ceeb87986d19bc"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8cc88d8-0221-5bee-82b2-736319f4b010",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42035 fix already exists in commit b9e4e1b49f5f62215e46c059f343b2e9ccb81c39"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13effce5-99fe-5690-b281-1219060eab41",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42036 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42036 fix already exists in commit db7082ebbf0cf245e8d001407b789a154606afac"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5d19467-7bcd-5e1c-907d-f671370a33ad",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e73325-39a7-5a9d-901a-2649218daaa0",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42038 fix already exists in commit 38fbaef2676858fc97ea981cf9e2fabf343e60a4"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:969ce18b-7682-5487-aa72-5c0442c4c704",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42039 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42039 fix already exists in commit da36cba07a133fa5f833556303db0e3e5ce3dc87"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f766027-b5b8-5c7a-a1bb-4050102218cb",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0b81045-ba7a-5eef-89d3-e72481fa1a8b",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42041 fix already exists in commit 935b8c002f9b50ff36d4f0ed3b6be5fc855a0b6e"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d10a2fdc-8ee7-51f9-a90e-b82a506f2e1b",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42042 fix already exists in commit be54ef4e740e14b267e765f8e42ff9104d78bc8b"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e2e8d7-3d1f-54f4-b818-67382dd99ec8",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.6.8-tuxcare.3 of axios. CVE-2026-42043 fix already exists in commit 2a6288f317a7bfc46a41088a3809a22e8193340a"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f8150f-37de-570c-bae0-85eb9f657289",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:152826ca-340e-5bba-b44f-9eb6455c6269",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d6b4be8-aca2-59cd-90c1-32157f083c9a",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca19c81b-e4ce-594d-ad4f-c97ceca4cade",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7770155b-fd33-5402-b914-535e61fcbad2",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc5b076a-8d12-5541-9439-fa84ea50f956",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 1.6.8-tuxcare.3 of axios. not_affected \u2014 axios v1.6.8 is not affected by CVE-2026-44492. The vulnerable code (lib/helpers/shouldBypassProxy.js) was introduced in v1.15.0, and v1.6.8 predates this entirely. The target uses a different architecture (proxy-from-env only) that is outside the scope of this CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1060f723-7b48-5c8b-9704-ed0713d50035",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44494 affects version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d52d348-f5b7-59ef-9631-659b86c911a5",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a19b94-6007-560e-9870-f1991e344ffa",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d40a330d-d60f-5f29-8394-94531dd47d2e",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98de84ed-da25-5a56-a861-b0c94fbb3fda",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24ec3768-68b8-5e73-8e68-b95ba1f9478d",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:834881ff-b6a4-5e50-ab82-118fb8b3ee13",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.6.8-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.6.8-tuxcare.3"
    }
  ]
}