{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:72e04d90-b349-55f2-9e13-ee87487198fe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nuxi@3.2.0-tuxcare.5",
      "type": "library",
      "name": "nuxi",
      "version": "3.2.0-tuxcare.5",
      "purl": "pkg:npm/nuxi@3.2.0-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c06269a6-2043-5a68-9df7-f10e6763921e",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7645fcc-ec09-5988-9ad2-905c86f38b58",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b408f68-7b54-5fec-89fe-aa15adff9a6e",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c78181-1aac-5e38-9c60-74cf31cdb5c0",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbc0fcbb-7b3b-5cc3-b3c6-8b4d43facda4",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb8da3c-d189-5014-8f08-9c3d42833fca",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:866ebf66-50ee-5b2b-bfaa-7a1eae9daee8",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9433dc9b-5b98-522a-ab0e-8429ca3c3fd0",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a325f40-eef8-5752-bdf5-3d5a59f3bab0",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cdd2d49-80ac-5b4f-a810-ff72b2425631",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82aaf22d-3aa3-5b81-94b5-5808b7baa31d",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:576652ed-0f35-5af7-bd2a-e2b7363ad762",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be2fcd81-a913-5c49-9244-44e604d88fcf",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed034d3f-0caa-53a6-93ad-2e8ddb8046a3",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b43f032d-c4fa-5bff-9993-b4804ef45122",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for nuxi 3.2.0-tuxcare.5. CVE-2022-25852 is a false positive for this repository. The CVE affects pg-native and libpq npm packages (PostgreSQL database client bindings), but this repository is the Nuxt.js web framework (version 3.2.0-tuxcare.4). Exhaustive containment search found no pg-native/libpq code in the repository - not as the project itself, not as a vendored/bundled copy, and not as a declared dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e4a47c3-f800-571c-ba30-3fedcd4abdcf",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef9147a7-dbb3-581e-86bb-8fd453ccbb98",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34343 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c904f9c1-d5c5-5295-a8fe-ad9572798247",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85df14b8-ce10-5dd0-bd80-4f4017893c7a",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5ad463-e67e-5037-9395-ba903828bf4e",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89d1b4d9-999e-5f3b-acc5-b7a44c26d618",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55889585-6ee3-5c46-99ec-69a7b47bed52",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd26c53-5e73-5940-a9ee-3e44e6a5b0d0",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b16e79b-6fe1-57c6-88ad-26b87b4a6995",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for nuxi 3.2.0-tuxcare.5. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e22b8e-3961-503c-a369-30ff1bb20a5a",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45669 does not affect version 3.2.0-tuxcare.5 of nuxi. not_affected - CVE-2026-45669 requires the SSR redirect body that navigateTo(url, {external:true}) builds in packages/nuxt/src/app/composables/router.ts (nuxtApp.ssrContext['~renderResponse'] with only the double quote percent-encoded). In nuxt 3.2.0 that code does not exist: the server-side external branch of navigateTo delegates to h3 sendRedirect(event, redirectLocation, code) and builds no HTML body. Grep over the branch: '%22' - 0 hits in source, 'renderResponse' - only packages/nuxt/src/core/runtime/nitro/renderer.ts. The sink appears in later majors: 4.0.3 has it and carries patches/CVE-2026-45669.patch."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4e2988-8084-5cf2-9ebf-cbee9cfd5f47",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15927108-d856-5a9b-a4e5-7e03f4534aaa",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.5 of nuxi. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17f59871-a00e-5c04-a94f-78936038468a",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d01086aa-ed3a-53eb-a87c-743afe27f5ef",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20f4e8a5-3e2f-53ca-a1d6-e01b5fd6eb58",
      "id": "CVE-2026-56317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56317 is fixed in version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc2bf13-7107-5a92-a5f5-aee294b30a4e",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.5 of nuxi. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12fbf112-6696-52ae-b08f-5583c09381c9",
      "id": "CVE-2026-71314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0bce645-bd5c-5ec3-a397-43330f4f0891",
      "id": "CVE-2026-71316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 3.2.0-tuxcare.5 of nuxi. Nuxt.js version 3.2.0 is not affected by CVE-2026-71316. The vulnerability requires runtime payload caching (introduced in Nuxt 4.x) where _payload.json entries are served before route middleware. Version 3.2.0 only has build-time prerender cache (null during runtime), uses _payload.js files (not .json), and all runtime payload requests undergo full SSR rendering with route rules enforcement. The vulnerable code path (runtime cache bypass) does not exist in this version's architecture."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba963a2-ac3e-5c43-854c-c93b8dedf616",
      "id": "CVE-2026-71318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7f370e5-c1d6-5947-a836-02cb7a447c71",
      "id": "CVE-2026-71321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 3.2.0-tuxcare.5 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82eb0f15-1585-583c-9a13-ef8b460fd67e",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.5 of nuxi. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff807bde-e06e-5bc0-b10f-fe21c785bdf9",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.5 of nuxi. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:289ced71-3517-5741-807d-e38362ad4e5e",
      "id": "GHSA-xppm-jmw6-fhmf",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-xppm-jmw6-fhmf is a false positive for nuxi 3.2.0-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nuxi@3.2.0-tuxcare.5"
    }
  ]
}