{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c3af8915-165b-534e-bb37-7c0b9697bb27",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-astro@3.6.5-tuxcare.6",
      "type": "library",
      "name": "create-astro",
      "version": "3.6.5-tuxcare.6",
      "purl": "pkg:npm/create-astro@3.6.5-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:94e8736d-b8b1-5e59-86be-78e8ed0e478b",
      "id": "CVE-2024-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64a26c4e-931d-5d55-adf1-2da0db006032",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65501d85-6cbb-5db2-a68b-ebb921d8fa21",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61adc59a-00b9-5700-81d5-fcabe452137a",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d1646e-fcd6-5eae-8290-56c03d20e259",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c12819fd-acc8-5480-ad30-f7beaf4e9d05",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55000dfc-2744-5a20-a691-6c46cc9bae1a",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e74caf-42e1-5b13-b13b-e38e4ded5c0e",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cca072c-2a1a-50b7-a80e-c3737dadf8b8",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a83049e-c898-51c8-88b3-91b28af72d79",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42ee81dd-21cf-56dd-86e9-b37059eb6f78",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02015945-bb23-5462-9fc2-bdff8c0fb147",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd24b757-b2bc-5d17-9d9c-f5eda446a997",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c32b98-c73e-52f0-b2fe-3cf5c4023a43",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.6 of create-astro. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con..."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5acd664-507d-5919-864d-561faf2d9d14",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7360aee5-a3e8-54bb-8bb1-3d257f828277",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e4ccf71-f818-5d92-833f-5341c443597d",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8341ce3a-c651-53d7-ab9b-4baf5f356799",
      "id": "CVE-2026-59728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:958b08d4-1eb1-5a3b-a7b7-84440fe219d8",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6198aba7-a317-542e-8389-de0926063dda",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be7230b-f7fc-5fef-b052-01cabd76130b",
      "id": "CVE-2026-84376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-84376 affects version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566c3660-c7c8-5502-a440-1e8f59f924bc",
      "id": "GHSA-26w7-cxv4-gfx2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26w7-cxv4-gfx2 affects version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57dcf96c-6efe-5d0e-97ca-1f1d99d2095a",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 3.6.5-tuxcare.6 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-astro@3.6.5-tuxcare.6"
    }
  ]
}