{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d9a9a02e-7fcd-5a1c-87ec-006be2842738",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1",
      "type": "library",
      "name": "lodash.unescape",
      "version": "3.2.0-tuxcare.1",
      "purl": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:eee08581-3ec5-5e13-b596-cfe4ac1b27fd",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c1d5ab-5000-56aa-be99-e1c3c450a159",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99e2571-4c0f-55c0-a6cf-a4368ab61819",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3e78af8-a02c-54cb-9563-8c061dfb4e19",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c551f36b-bacd-5317-af4a-e97187569565",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adb887d9-a2d5-51de-aa8f-8fe97411a993",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91b5ec90-681d-53bd-8bd3-bc856e827252",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89887084-8f57-5622-a76b-b7d8580e6400",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84eef81d-9685-573d-801c-b090d29f6bee",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf756566-ba96-5333-8661-117a3b1e73e4",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ece7a9ef-fd06-5c26-a90e-6d01be5c097a",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e97b78ef-730d-5c23-93a6-16958eadd0e8",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-8203 affects version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253e5bef-fb13-54b4-b63c-0b404bd8f72d",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:824bb075-2637-50a8-b003-3da1d38fd542",
      "id": "CVE-2021-41720",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41720 is a false positive for lodash.unescape 3.2.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1bb815f-3a32-52a8-a90d-daaf54f4c252",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8907e65-094e-56fb-bd7c-5cc575d8a164",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d8fd71-56be-5ac8-9e7d-074c66ae4ae6",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea5c03d-f2af-5f47-bb4c-ef51a2364220",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aaca2a2-b860-559f-8d3b-d0094c5bfb21",
      "id": "CVE-2025-13465",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-13465 does not affect version 3.2.0-tuxcare.1 of lodash.unescape. not_affected \u2014 Lodash 3.2.0 is not affected by CVE-2025-13465. The vulnerability requires the `baseUnset` function with unvalidated `delete` operations, which does not exist in lodash 3.x. The `_.unset` function (one of the two affected functions per the CVE) was introduced in lodash 4.x and is absent from this version. The `_.omit` function exists but uses a fundamentally different architecture: it creates a..."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f503790d-e89b-5976-85ee-2054bb54e8eb",
      "id": "CVE-2026-2950",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2950 does not affect version 3.2.0-tuxcare.1 of lodash.unescape. not_affected \u2014 Lodash v3.2.0 is not affected by CVE-2026-2950. The vulnerability requires path traversal via baseUnset (used by _.unset and _.omit in lodash 4.x), where array-wrapped path segments bypass string-only validation. Lodash v3.2.0 has a fundamentally different architecture: _.unset does not exist, and _.omit creates new objects by filtering properties rather than deleting along paths. The vulnerabl..."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:336d15cf-0f12-5fb9-b98b-28df4f6affe5",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33151 affects version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c01ce2-87c2-5d09-9aa6-b1b49cb4e3cb",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 3.2.0-tuxcare.1 of lodash.unescape."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash.unescape@3.2.0-tuxcare.1"
    }
  ]
}