{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:36e12d33-a9cd-569c-ad44-5d5395b5d7f6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2",
      "type": "library",
      "name": "@astrojs/db",
      "version": "4.16.19-tuxcare.2",
      "purl": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ae7dd077-62fd-576c-9e87-8ba743bf0cbe",
      "id": "AIKIDO-2025-10879",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10879 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366ba20e-dca6-59d6-a557-675cc0c06a0c",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55303 affects version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e768b8f9-44e0-53fc-9941-0eb43d0ece2c",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4c0bd2-d4fa-5b2e-8f79-bc66af72499a",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdf79196-a4b5-5129-913e-05b434aa05cc",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86f767fa-6741-5690-aeba-e2addd5ea7be",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9780bf4-ad6c-5bfb-a19a-0ce372cb4ddc",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f0341d4-b1c5-5a82-9495-4fd533658cf9",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e73a0618-2f42-55f4-8ef3-af03e78b397d",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ca9f5a0-3552-5987-ba58-79a3d131a536",
      "id": "CVE-2026-33490",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33490 is a false positive for @astrojs/db 4.16.19-tuxcare.2. false_positive \u2014 CVE-2026-33490 concerns H3 (a minimal HTTP framework), but the target repository is Astro (a website build tool). H3 is not present in this repository - no vendored code, no dependency, no imports. The only 'h3' references found are HTML heading components (<h3> tags), unrelated to the H3 framework."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98eb3ee-a189-5a8d-8520-6b637032f9ca",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d51f6b7-48e1-5216-a528-a258152a9b91",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4100de20-d4a6-51f2-bd8c-e05e70801d48",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45028 affects version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b551dd21-2a1f-561b-9efa-f6893cd48ce2",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e5b946-979d-5629-ba8b-b92058f5edcd",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9761c4db-9cdb-5ec1-9e58-8886f5d1d6bb",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 4.16.19-tuxcare.2 of @astrojs/db. already_fixed \u2014 The target repository has already fixed this vulnerability via CVE-2026-25545 / AIKIDO-2025-10879 (May 7, 2026), which addresses the identical SSRF issue. The fix removes the prerendered error page fetching feature entirely, replacing it with direct SSR rendering. This is a more aggressive mitigation than the upstream's host validation approach."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c94cda9c-266b-588d-a447-7990e52a8eec",
      "id": "CVE-2026-59727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59727 affects version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d28a4e61-2cf5-5a57-a21d-54608ba072e6",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94ea7e21-1373-5390-b20c-ad5a85156586",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 4.16.19-tuxcare.2 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/db@4.16.19-tuxcare.2"
    }
  ]
}