{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a69f9696-c22d-5385-bd2f-5ec7ee52e3b3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2",
      "type": "library",
      "name": "@astrojs/prism",
      "version": "4.16.19-tuxcare.2",
      "purl": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:35ee674a-00b4-57ac-a376-245ce82c4b4c",
      "id": "AIKIDO-2025-10879",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10879 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71129e0c-56bb-5017-b53a-4f7130f1811f",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55303 affects version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f4de62-51e4-5f3c-ac5b-9f06aa79aade",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e634c223-8cc6-5fc7-ad67-48e736498aaf",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:703f21e9-519a-5f45-a813-5211161e2525",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fca9294-930a-5b81-b52f-9cafdc4cc586",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d86291b5-4736-5c4b-8802-0081686c5a55",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae174f51-a54b-59aa-b0a7-6c2cc0c2b841",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5c3105b-789e-5e42-a886-fa3a95b17dde",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4651d81-b318-5778-9df2-5bbca87e51ef",
      "id": "CVE-2026-33490",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33490 is a false positive for @astrojs/prism 4.16.19-tuxcare.2. false_positive \u2014 CVE-2026-33490 concerns H3 (a minimal HTTP framework), but the target repository is Astro (a website build tool). H3 is not present in this repository - no vendored code, no dependency, no imports. The only 'h3' references found are HTML heading components (<h3> tags), unrelated to the H3 framework."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2c9835-c074-5c3d-b3d4-7677bcfb0e67",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:783efa6c-dad7-571e-8d71-58445f7d42df",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a064fd4d-1b2d-5b6d-8366-845b94849d9f",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45028 affects version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caa0e057-5d4a-52fc-9d19-92d53fe4495d",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de87a8bd-c075-5caa-808e-f3c5a310c330",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5c3983-8c0b-5fa9-8ea6-94352df0cba1",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 4.16.19-tuxcare.2 of @astrojs/prism. already_fixed \u2014 The target repository has already fixed this vulnerability via CVE-2026-25545 / AIKIDO-2025-10879 (May 7, 2026), which addresses the identical SSRF issue. The fix removes the prerendered error page fetching feature entirely, replacing it with direct SSR rendering. This is a more aggressive mitigation than the upstream's host validation approach."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb0238d1-a127-519d-8781-e6bc097598cd",
      "id": "CVE-2026-59727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59727 affects version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca4a953-76fd-514e-b60b-31ec04f80371",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e0df65-4140-54bd-b805-7a89dbb0be58",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 4.16.19-tuxcare.2 of @astrojs/prism."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/prism@4.16.19-tuxcare.2"
    }
  ]
}