{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7ffa53c4-872d-54db-a87b-9bec5d54d95f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "psr7",
      "version": "1.4.2-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7f13d214-cfaa-521c-b5eb-c52c1c6f7b65",
      "id": "CVE-2022-24775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24775 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91a7897-0a04-5dec-a660-4e6c18b43e54",
      "id": "CVE-2023-29197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-29197 does not affect version 1.4.2-p1+tuxcare of guzzlehttp/psr7. Version 1.4.2 is not vulnerable. Summary: CVE-2023-29197 does NOT affect version 1.4.2. The vulnerable code (header validation regex without /D modifier) was introduced ~3 years AFTER this version (in commit 092dbc2 on 2020-01-09, first appearing in version 2.0.0). Version 1.4.2 predates the introduction of the assertHeader() and assertValue() validation methods entirely. Since the vulnerable code pattern was never present in this version, it is not vulnerable to this specific CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce7702a-414d-5371-b413-0b8de79eec75",
      "id": "CVE-2026-48998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48998 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d9e051-ad82-51b4-9166-cd3f542c444a",
      "id": "CVE-2026-49214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49214 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e90a7ce-c94e-56ef-8158-3e523d0e3641",
      "id": "CVE-2026-55766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55766 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:158b2abb-2747-5e51-ac2b-c81b0997dab2",
      "id": "CVE-2026-59882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59882 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
    }
  ]
}