{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ec951580-a78d-5429-9439-6f3a3278257b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9",
      "type": "library",
      "name": "nodemailer",
      "version": "6.10.1-tuxcare.9",
      "purl": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0a1b044f-5d84-5ae9-99fb-8707ef01b4b9",
      "id": "CVE-2025-13033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13033 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a306b60-061e-5956-b6b0-420855cc36c3",
      "id": "CVE-2025-14874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14874 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528b5e5a-33c0-5de4-abc8-71e90936c0f2",
      "id": "CVE-2026-82659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82659 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26935f25-31e8-5319-8e24-e119b45fc56f",
      "id": "CVE-2026-82660",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82660 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:885b36f0-fa04-59dd-8fa1-829eaea4fb46",
      "id": "CVE-2026-82661",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82661 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:300774f3-2954-5831-966c-fcd66a944c46",
      "id": "CVE-2026-82662",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82662 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0fad9c-a10f-5f46-ab08-6221d966dcb0",
      "id": "CVE-2026-82853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82853 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1986adfa-63cd-57ce-9b80-0eb17425efba",
      "id": "CVE-2026-82854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82854 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf072f69-862a-57ab-bfb4-e1789d8e4804",
      "id": "GHSA-268h-hp4c-crq3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-268h-hp4c-crq3 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b8b7b02-a657-5ee0-a62e-c7fc0df6e703",
      "id": "GHSA-2x7j-588g-ccc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-2x7j-588g-ccc2 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4921778c-249e-50c4-ae4a-af22ee27a502",
      "id": "GHSA-46j5-6fg5-4gv3",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-46j5-6fg5-4gv3 is a false positive for nodemailer 6.10.1-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d53b99f7-379c-518d-b638-2be74d3f696e",
      "id": "GHSA-8m3c-c648-2xjj",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8m3c-c648-2xjj affects version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc4e242-7146-53e5-9742-4b4fd50ec8ad",
      "id": "GHSA-c7w3-x93f-qmm8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c7w3-x93f-qmm8 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:619ea05a-7d71-53c3-bb92-c34007bd2484",
      "id": "GHSA-cc9r-2j5m-2m83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cc9r-2j5m-2m83 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b58a6d-b88d-5eaa-9cf9-217b17d84fe7",
      "id": "GHSA-h3hj-cmcx-xc66",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-h3hj-cmcx-xc66 is a false positive for nodemailer 6.10.1-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c5353b7-b49b-5e27-95de-b7653a7d7d16",
      "id": "GHSA-jj37-3377-m6vv",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-jj37-3377-m6vv is a false positive for nodemailer 6.10.1-tuxcare.9."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af5f3551-ac27-5f58-9249-f6542202b96a",
      "id": "GHSA-mm7p-fcc7-pg87",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mm7p-fcc7-pg87 does not affect version 6.10.1-tuxcare.9 of nodemailer. already_fixed \u2014 The target repository (nodemailer 6.10.1-tuxcare.3) already contains the complete security fix for CVE-2025-13033/GHSA-mm7p-fcc7-pg87. The fix was backported by TuxCare on December 9, 2025 via commit 189d7aa. The vulnerability involved incorrect parsing of quoted local-parts containing @ symbols, which could cause email misrouting to attacker-controlled domains. The fix adds quote state trackin..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b3f82f9-eb58-574c-a6c4-46c377fa338c",
      "id": "GHSA-p6gq-j5cr-w38f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-p6gq-j5cr-w38f is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c75ec11-7f54-546a-baf3-c60fee2e1467",
      "id": "GHSA-r7g4-qg5f-qqm2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-r7g4-qg5f-qqm2 is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f92d6785-1dff-5da5-a609-cf5d4dc0bc05",
      "id": "GHSA-vvjj-xcjg-gr5g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vvjj-xcjg-gr5g is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eeecace-b5f4-5f6b-98e7-82a455ca6c98",
      "id": "GHSA-wmmp-3585-3rmp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wmmp-3585-3rmp is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:749bce93-ce35-562c-a199-a926157ed872",
      "id": "GHSA-wqvq-jvpq-h66f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wqvq-jvpq-h66f is fixed in version 6.10.1-tuxcare.9 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.9"
    }
  ]
}