{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:974dee66-e377-560d-8d60-364268854e9a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/mysql2@2.3.3-tuxcare.5",
      "type": "library",
      "name": "mysql2",
      "version": "2.3.3-tuxcare.5",
      "purl": "pkg:npm/mysql2@2.3.3-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:368e68fd-3ae7-52fb-912f-09cac35aa7c2",
      "id": "AIKIDO-2026-10225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10225 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54391740-cb55-5715-9ddc-f53a67195510",
      "id": "CVE-2017-1000048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-1000048 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aae76b55-e18a-5410-87e6-2d5d772f9b6d",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4601452c-1a8b-50f5-9efa-1fdc8a425228",
      "id": "CVE-2017-20165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20165 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea694d77-05e2-5875-90e0-d7b98fd01fa4",
      "id": "CVE-2022-24999",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24999 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7380a41f-c18f-5d35-8546-c695304da251",
      "id": "CVE-2024-21507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21507 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48bf41f0-4ae7-5058-97f1-6cace468c205",
      "id": "CVE-2024-21508",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21508 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356fb44a-13f4-5224-828f-91256183922b",
      "id": "CVE-2024-21509",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21509 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7d3b019-69d6-5dd7-bece-177e9594efc2",
      "id": "CVE-2024-21511",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21511 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3656cf59-f548-59ef-a0d5-4e513b4d500c",
      "id": "CVE-2024-21512",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21512 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac206132-c245-5d5b-b84c-e1fb64e71b23",
      "id": "CVE-2025-15284",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15284 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9529c1df-0229-583f-a400-ea89f1ee47e6",
      "id": "CVE-2025-7783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-7783 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f947d91c-c215-53e0-882f-83e01e7a03ee",
      "id": "CVE-2026-12143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-12143 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa9fee7-2fa4-5f42-9f5a-8a285db3d7c6",
      "id": "GHSA-3f6p-5ww8-9rcr",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-3f6p-5ww8-9rcr does not affect version 2.3.3-tuxcare.5 of mysql2. not_affected \u2014 Version 2.3.3-tuxcare.6 is NOT AFFECTED by GHSA-3f6p-5ww8-9rcr. The vulnerable mysql_clear_password authentication plugin does not exist in this version. The plugin was only introduced in v3.0.0-rc.1 (March 2022), well after v2.3.3 was released (November 2021). When a rogue server requests the mysql_clear_password plugin via AuthSwitchRequest, the library rejects it with error \"Server requests ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff3c4be-c6b5-5c20-8c08-f981855ce0c7",
      "id": "GHSA-rgwj-5xj2-c3m3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rgwj-5xj2-c3m3 affects version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba5d006d-8956-52ba-a6c2-10f0ece9e065",
      "id": "GHSA-v2p6-4mp7-3r9v",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2p6-4mp7-3r9v is fixed in version 2.3.3-tuxcare.5 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
    }
  ]
}