{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5a7d2d6e-bbf8-5c5c-9fed-97287217b966",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1",
      "type": "library",
      "name": "lodash.words",
      "version": "3.2.0-tuxcare.1",
      "purl": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:05c9feb0-530d-51ab-9e5f-52354e24eb28",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:764baa0b-861e-52fb-9554-eeacc32ffcf3",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63066a31-dd2b-58dd-9a46-34ddc17aa0bd",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54f772c-6371-5c50-80b6-f86a636668d8",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:890a8c11-2b0e-57fa-b3bb-472fb27a5bc1",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8d705ca-a31a-5a8f-b280-b83f7abbee77",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2240157-501c-5d9c-aa9f-58678004d12b",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b4daac-2e5c-589d-8ce2-bbe36906eed8",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c60470-3195-5c60-a634-a84199038a4d",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b0d7eec-bc69-5e25-b36c-f823f0e91f7f",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe590de5-8e71-5d8d-a8f1-5e35fde1d205",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d545e132-d451-59c3-aeb4-3c9e8ff2deff",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-8203 affects version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aaa3888-d716-5ca2-879f-0717858ddb14",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca53c50-c397-5b7d-8e2f-25cc6e98313b",
      "id": "CVE-2021-41720",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41720 is a false positive for lodash.words 3.2.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec58fa8-faec-5afc-9446-6a60f762530e",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae2efff-8465-54c0-b75c-ffc0c928ad45",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfa9d7cf-a63d-5ab8-b66c-d88a5dfe7145",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d609ac-b5c1-58a9-a52e-7b78b1e15a6c",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be8acf1b-601e-5fa5-8a94-b1d4181bf73e",
      "id": "CVE-2025-13465",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-13465 does not affect version 3.2.0-tuxcare.1 of lodash.words. not_affected \u2014 Lodash 3.2.0 is not affected by CVE-2025-13465. The vulnerability requires the `baseUnset` function with unvalidated `delete` operations, which does not exist in lodash 3.x. The `_.unset` function (one of the two affected functions per the CVE) was introduced in lodash 4.x and is absent from this version. The `_.omit` function exists but uses a fundamentally different architecture: it creates a..."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3da7ee5c-83f8-55b2-8803-111ddb21ba6f",
      "id": "CVE-2026-2950",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2950 does not affect version 3.2.0-tuxcare.1 of lodash.words. not_affected \u2014 Lodash v3.2.0 is not affected by CVE-2026-2950. The vulnerability requires path traversal via baseUnset (used by _.unset and _.omit in lodash 4.x), where array-wrapped path segments bypass string-only validation. Lodash v3.2.0 has a fundamentally different architecture: _.unset does not exist, and _.omit creates new objects by filtering properties rather than deleting along paths. The vulnerabl..."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948cabfc-3803-5b70-b52c-1dac7fabaf6a",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33151 affects version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6d70252-2c15-5589-b9f9-bb74bc47ace7",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 3.2.0-tuxcare.1 of lodash.words."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash.words@3.2.0-tuxcare.1"
    }
  ]
}