{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:98461a85-65d8-56e5-9695-b22221268e0e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3",
      "type": "library",
      "name": "nodemailer",
      "version": "0.7.1-tuxcare.3",
      "purl": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:35f56700-21ec-5c9e-aab6-fa160f825a6f",
      "id": "CVE-2017-20162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20162 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:845ddc8c-1cee-5567-a74a-d82c69f6a5bb",
      "id": "CVE-2020-7769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7769 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d946db-779a-59f5-a455-4b5a3ae484f1",
      "id": "CVE-2021-23400",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-23400 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 is not affected by CVE-2021-23400. The vulnerability exists in nodemailer's internal address formatting code (lib/mime-node/index.js _normalizeAddress method) introduced in later versions (4.x+) when mailcomposer was internalized. Version 0.7.1 uses external mailcomposer package (~0.2.10) for all address formatting and does not contain the vulnerable code pattern in its own codebase."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b7f0739-80e3-5f19-a0af-6f74fe0dd9e4",
      "id": "CVE-2024-58379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-58379 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb916371-c897-5f4b-9c84-cc74ae2ac607",
      "id": "CVE-2025-13033",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-13033 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 does not contain the vulnerable addressparser module. The addressparser was introduced in nodemailer v3.0.0 (January 2017), years after version 0.7.1. The vulnerability pattern (email address extraction from text tokens using regex) does not exist in 0.7.1's architecture."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1b18ecf-0e11-56ac-838a-13300565b7ed",
      "id": "CVE-2025-14874",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-14874 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 is not affected by CVE-2025-14874. The vulnerable lib/addressparser/index.js module with recursive group-flattening logic was introduced in v3.0.0 (2017-01-31), 2.5 years after v0.7.1 (2014-07-09). Version 0.7.1 uses a different architecture where address handling is delegated to the mailcomposer external dependency, and contains no recursive address parsing code."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0fece8c-e8e8-5852-8bfe-d3941037d2a9",
      "id": "CVE-2026-82659",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-82659 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 The target repository (nodemailer v0.7.1-tuxcare.1) is NOT AFFECTED by CVE-2026-82659. This CVE describes a vulnerability in nodemailer v9.0.0's internal mail-composer component where the message-level `raw` option bypasses `disableFileAccess`/`disableUrlAccess` security flags. Version 0.7.1 has a fundamentally different architecture: it uses mailcomposer as an external npm dependency (~0.2.10)..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085ebe93-71df-51ad-ab36-3c922dcc1497",
      "id": "CVE-2026-82660",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82660 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29aaf845-b919-55cc-b8e7-68ad76ec0af9",
      "id": "CVE-2026-82661",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82661 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e3f8677-82f0-5fec-88ac-6d7815aa1992",
      "id": "CVE-2026-82662",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82662 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d08118f1-0ff0-5f6f-9d98-b3ddb05ac51d",
      "id": "CVE-2026-82853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82853 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02179e42-4be0-5bee-8850-4d03a1d9257a",
      "id": "CVE-2026-82854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82854 is fixed in version 0.7.1-tuxcare.3 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b1f7c8-243e-5d5a-838d-7c2ef1e9c0cb",
      "id": "GHSA-268h-hp4c-crq3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-268h-hp4c-crq3 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 does not contain the List-* header functionality that is vulnerable to CRLF injection. The entire `list` message option and associated header generation code does not exist in this architecture."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b37050b7-8ea4-5194-8dd9-cb1ecfc9efc4",
      "id": "GHSA-2x7j-588g-ccc2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-2x7j-588g-ccc2 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Nodemailer 0.7.1 is not affected by GHSA-2x7j-588g-ccc2. The vulnerable code (lib/addressparser/ module with quadratic-time concat/splice/deduplication operations) was introduced in nodemailer 3.0.0 and does not exist in version 0.7.1. Version 0.7.1 uses a fundamentally different architecture that delegates all email address parsing and message composition to the external mailcomposer dependenc..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cff7ae52-6a39-5d2a-ae8e-06847b247040",
      "id": "GHSA-46j5-6fg5-4gv3",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-46j5-6fg5-4gv3 is a false positive for nodemailer 0.7.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3394be63-53a3-5647-ac9e-df9b4be8d6d8",
      "id": "GHSA-8m3c-c648-2xjj",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-8m3c-c648-2xjj does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 is not affected by GHSA-8m3c-c648-2xjj. The vulnerability describes a bypass of Nodemailer's security sandbox options (disableFileAccess/disableUrlAccess) through a legacy resolveContent() API path. These security sandbox features were introduced in version 3.0.1, which postdates the target version 0.7.1 by multiple major versions. The target uses a completely different architectu..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17a5e75c-58b3-5413-aa93-0011538c50ef",
      "id": "GHSA-9h6g-pr28-7cqp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-9h6g-pr28-7cqp does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Nodemailer version 0.7.1 is not affected by GHSA-9h6g-pr28-7cqp. The ReDoS vulnerability exists in data URI parsing functionality that was not introduced until version 1.2.2. Version 0.7.1 does not contain any data URI processing code and therefore cannot be exploited via this attack vector."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b313b801-2e32-5975-bb8e-7e3cd3e306a9",
      "id": "GHSA-c7w3-x93f-qmm8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c7w3-x93f-qmm8 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Nodemailer version 0.7.1 is not affected by GHSA-c7w3-x93f-qmm8. This version uses a fundamentally different architecture where all SMTP protocol handling and command construction is delegated to the external 'simplesmtp' npm package. The vulnerable code path (lib/smtp-connection/index.js with unsanitized envelope.size concatenation into MAIL FROM commands) does not exist in version 0.7.1 and w..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ad3df1-72f1-5d83-b022-d7129bc00657",
      "id": "GHSA-h3hj-cmcx-xc66",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-h3hj-cmcx-xc66 is a false positive for nodemailer 0.7.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd0341f2-973b-5e0f-9b71-b474a186b988",
      "id": "GHSA-jj37-3377-m6vv",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-jj37-3377-m6vv is a false positive for nodemailer 0.7.1-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8be2799-6ea7-5a8d-aa01-e3df69b85aac",
      "id": "GHSA-p6gq-j5cr-w38f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-p6gq-j5cr-w38f does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 of nodemailer is not affected by GHSA-p6gq-j5cr-w38f. The vulnerability concerns bypassing disableFileAccess/disableUrlAccess security flags when using the message-level 'raw' option, but version 0.7.1 has neither the 'raw' message option nor the security flags. The target uses a fundamentally different architecture (external mailcomposer package) that predates the security model ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbba5402-f2b4-5f76-818c-69e5a8422f22",
      "id": "GHSA-r7g4-qg5f-qqm2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-r7g4-qg5f-qqm2 does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Nodemailer version 0.7.1 is not affected by GHSA-r7g4-qg5f-qqm2. The vulnerability concerns nodemailer's internal HTTPS fetch client (lib/fetch/index.js) that disables TLS certificate verification (rejectUnauthorized: false) when making OAuth2 token requests. Version 0.7.1 does not contain this vulnerable code path - it lacks both lib/fetch/ and lib/xoauth2/ directories and delegates all OAuth2..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0453ebf-6352-5980-b9e8-7ab44e2dc008",
      "id": "GHSA-vvjj-xcjg-gr5g",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vvjj-xcjg-gr5g does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 uses a fundamentally different architecture than the affected versions. The vulnerability exists in lib/smtp-connection/index.js (lines 1333, 1336, 1384, 1517, 1520) where modern nodemailer constructs EHLO/HELO/LHLO commands using unsanitized name input. Version 0.7.1 does not contain this file or code. Instead, it delegates all SMTP protocol handling to the external 'simplesmtp' ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45bbebb4-dbad-506b-9a40-e2b78650f2eb",
      "id": "GHSA-wmmp-3585-3rmp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-wmmp-3585-3rmp does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 is not affected by GHSA-wmmp-3585-3rmp. The vulnerability exists in nodemailer's integrated address normalization code (lib/mime-node/index.js _normalizeAddress function) that uses raw RFC-3492 Punycode encoding without UTS-46 normalization. This code path was introduced in later versions (post-6.x architecture) and does not exist in version 0.7.1. Version 0.7.1 uses a fundamental..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27895d95-9c5b-54ac-8b2f-b668d2362e6d",
      "id": "GHSA-wqvq-jvpq-h66f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-wqvq-jvpq-h66f does not affect version 0.7.1-tuxcare.3 of nodemailer. not_affected \u2014 Version 0.7.1 does not contain the vulnerability pattern described in GHSA-wqvq-jvpq-h66f. The vulnerability requires jsonTransport feature and disableFileAccess/disableUrlAccess security controls to exist so they can be bypassed. Version 0.7.1 uses a fundamentally different architecture that predates these features entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nodemailer@0.7.1-tuxcare.3"
    }
  ]
}