{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b963749d-d25b-54fd-aa44-ed819b48f33b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/mysql2@2.3.3-tuxcare.6",
      "type": "library",
      "name": "mysql2",
      "version": "2.3.3-tuxcare.6",
      "purl": "pkg:npm/mysql2@2.3.3-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dfe8844c-4316-5d27-86c8-5212fd65decd",
      "id": "AIKIDO-2026-10225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10225 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57d295ec-cf86-52e0-9178-5fe17e4b0df5",
      "id": "CVE-2017-1000048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-1000048 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49b0aef-b2d8-5ee1-b2cf-16eb07eea48a",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a26a765b-8583-5f6a-8033-6e7b88ad2876",
      "id": "CVE-2017-20165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20165 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41009136-07ad-5fe0-bc5c-930eecc35b4f",
      "id": "CVE-2022-24999",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24999 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce49394e-f48e-500a-ab44-0c68f5e0c7c4",
      "id": "CVE-2024-21507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21507 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7670d868-8a17-5808-aba3-b8b0933d0840",
      "id": "CVE-2024-21508",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21508 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbda9fd4-8bee-531d-808a-c6a8c76382e9",
      "id": "CVE-2024-21509",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21509 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b44e5fba-cba5-5487-8376-8fcaf93af8b0",
      "id": "CVE-2024-21511",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21511 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed44a578-2745-56bd-8d5c-157012f7cd4c",
      "id": "CVE-2024-21512",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21512 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0338eaa-e0eb-5967-aa03-5aa0a83ec202",
      "id": "CVE-2025-15284",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15284 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9513b892-169d-5d90-b8f0-6fe22613d9d0",
      "id": "CVE-2025-7783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-7783 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c92d413d-b580-5241-9e28-814921f59469",
      "id": "CVE-2026-12143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-12143 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55a27dd9-0069-597f-a971-b4f842127be9",
      "id": "GHSA-3f6p-5ww8-9rcr",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-3f6p-5ww8-9rcr does not affect version 2.3.3-tuxcare.6 of mysql2. not_affected \u2014 Version 2.3.3-tuxcare.6 is NOT AFFECTED by GHSA-3f6p-5ww8-9rcr. The vulnerable mysql_clear_password authentication plugin does not exist in this version. The plugin was only introduced in v3.0.0-rc.1 (March 2022), well after v2.3.3 was released (November 2021). When a rogue server requests the mysql_clear_password plugin via AuthSwitchRequest, the library rejects it with error \"Server requests ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e96a1c95-ec60-57a3-b1de-5ec5b17873c1",
      "id": "GHSA-rgwj-5xj2-c3m3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-rgwj-5xj2-c3m3 is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e710f02-69c5-5059-a3ee-7dd9b8f05f71",
      "id": "GHSA-v2p6-4mp7-3r9v",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2p6-4mp7-3r9v is fixed in version 2.3.3-tuxcare.6 of mysql2."
      },
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/mysql2@2.3.3-tuxcare.6"
    }
  ]
}