{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:86c579ed-dcbb-5d8c-97f5-9d1bc24bf418",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1",
      "type": "library",
      "name": "@astrojs/webapi",
      "version": "0.26.1-tuxcare.1",
      "purl": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9aca2a8c-90b9-5913-9109-1fe4a6529444",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3745418a-f96e-5454-9318-dab2cc54a781",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea7d80fe-f641-5a38-ab6e-f60f4e8d78e5",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2494ba0c-9693-5c81-b634-357541931953",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b91d6d0-e007-58ad-b762-99914772090e",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f27f981-311b-51c3-97dd-057e0c90e59f",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ead7e1-c207-57a1-9802-8ed2a3d25a7c",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88e169de-0eb9-5138-865c-8f92a4140582",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2b9b75d-7c91-5017-9bda-f0cc8e3905b0",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e64a358-7e12-5249-a1d9-84fbb09efd63",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e6ffb44-9ef9-5b42-bbca-9de026050f90",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:081ebac4-dfca-5143-a49a-4e0e28f9f20f",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca870794-fbc3-52ce-b499-22fc96e5acca",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12f6206-3184-53c7-8fa1-20d775b4137b",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe30cdd-8d0c-57b6-8aaf-9235807fe3d9",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fce5f58b-18c1-54f1-b1c9-a52923019562",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63fc478d-11d3-596e-bf9a-e3b56e52b8df",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d754ef2-d94d-5a5e-b2e4-210177a6d458",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c11cdf3-886f-5a7d-8f49-75d4ed4fe313",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c7fbd70-19ea-5077-9a8f-e22f74e4f320",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db8272f6-093d-5017-9cd2-c57d8a186517",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e987d26-cc2c-5758-ac5e-7d8923d35ffc",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c42fae-ff6a-5ad1-b3df-a7641464a147",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22589aaf-8cc3-5d07-b3ff-ae461511a502",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa985c63-798c-5d0f-bc8b-c8951a693ee7",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42043 is fixed in version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50617106-8520-5b36-97e8-432b028c3ef3",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45028 affects version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:919615ff-ca66-56dd-8198-03a12e5e8e71",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50146 does not affect version 0.26.1-tuxcare.1 of @astrojs/webapi. not_affected \u2014 Version 0.26.1 uses a fundamentally different slot hydration architecture that predates the vulnerable pattern. The target creates a single template element with a marker attribute `data-astro-template` (no value), while the modern version interpolates slot names into the attribute value. The dangerous operation (slot name interpolation into HTML attributes) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e9d9de5-d5c4-5ed5-a1b0-7dbc6fbc7941",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54298 affects version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b071b63-73e3-5497-a657-02a87de7e611",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 0.26.1-tuxcare.1 of @astrojs/webapi. not_affected \u2014 Target version 0.26.1 does not have the prerendered error page feature that is vulnerable in modern Astro. The RouteData interface lacks the 'prerender' field, and the error handling infrastructure that fetches error pages over HTTP (default-handler.ts) does not exist. When errors occur, this version returns simple inline Response objects without making any HTTP requests."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf254d6c-7643-5c40-ad5e-2e2ea2dbcee3",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 0.26.1-tuxcare.1 of @astrojs/webapi."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d9c3ab-04bd-5e4e-8fa4-e90dcc791810",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 does not affect version 0.26.1-tuxcare.1 of @astrojs/webapi. not_affected \u2014 The target repository (Astro v0.26.1-tuxcare.1) is not affected by GHSA-4g3v-8h47-v7g6. The View Transitions feature, which is the source of the vulnerability, does not exist in this version. View Transitions were introduced much later in Astro v2.9+ (commit 6a12fcecb0, circa June 2023), while this target is from the early beta period (2021). The vulnerable code path (packages/astro/src/runtime..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/webapi@0.26.1-tuxcare.1"
    }
  ]
}