{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e03fe40-47e1-5cad-add4-be3f0e0d96b7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4",
      "type": "library",
      "name": "@next/react-refresh-utils",
      "version": "14.2.35-tuxcare.4",
      "purl": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d016a4f6-912f-5c0e-b738-cd55c4746839",
      "id": "AIKIDO-2026-10095",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10095 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50a5e168-3c53-5072-b729-60730f4934d2",
      "id": "AIKIDO-2026-10755",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10755 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c4a442-cd3a-59e2-8e75-dd1530e1aa7e",
      "id": "AIKIDO-2026-10757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10757 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca4242c5-9e66-536f-8322-dae75fe03a39",
      "id": "AIKIDO-2026-10758",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10758 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e60de6f-c7ec-57a1-942a-4397cdceb806",
      "id": "AIKIDO-2026-10762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10762 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bba9c61-455e-5d5c-83a0-374e92c3fc8b",
      "id": "CVE-2025-55173",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55173 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34921589-7cf3-5743-98a0-edffc1dba86f",
      "id": "CVE-2025-57752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57752 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74e5ec6f-86ca-5c8e-af2e-9429ad8d32b7",
      "id": "CVE-2025-59471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59471 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc3ebc23-2c6c-5a39-b423-1a5237270606",
      "id": "CVE-2025-59472",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59472 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea2d8aa-bc68-5238-b01e-93a56f70139d",
      "id": "CVE-2026-27980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27980 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d629e9b-8b61-5c0d-8fe2-68c6e132fccd",
      "id": "CVE-2026-29057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29057 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f80531b-ab81-5c73-87e3-45eaee0cd947",
      "id": "CVE-2026-44572",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44572 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da4abb95-54ea-5571-ab66-38911f91a0d7",
      "id": "CVE-2026-44573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44573 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bee9d9c-1e79-5d3d-88fd-3a67bfa22310",
      "id": "CVE-2026-44576",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44576 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d4c5a51-8979-54e5-b247-e39cf1394309",
      "id": "CVE-2026-44577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44577 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28caca6c-5569-5918-aa73-4b5ba4f57896",
      "id": "CVE-2026-44578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44578 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96fc6c2c-7223-5ebe-97f8-85646e15036c",
      "id": "CVE-2026-44580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44580 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38230f48-f699-5757-b106-a9be15e61a17",
      "id": "CVE-2026-44581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44581 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f6d84f-c232-514e-9858-f311d013b0a7",
      "id": "CVE-2026-44582",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44582 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b4255a2-0875-5431-bf61-d1c9290a25c1",
      "id": "CVE-2026-64641",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64641 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9b97f41-6e21-593c-b0c6-0d4f8a114572",
      "id": "CVE-2026-64643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64643 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a64567-4acf-5a64-9941-4a8d11564bf0",
      "id": "CVE-2026-64645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64645 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a17c80a2-dab3-5b00-860d-44856d236df0",
      "id": "CVE-2026-64646",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64646 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:379f392f-a294-567f-9a3e-baef05d0e232",
      "id": "CVE-2026-64647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64647 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74230b4-030b-5661-8660-52a6255155ce",
      "id": "CVE-2026-64648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64648 affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e73bd534-c853-5175-b7fe-520641db0c60",
      "id": "CVE-2026-64649",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-64649 does not affect version 14.2.35-tuxcare.4 of @next/react-refresh-utils. not_affected \u2014 Target version 14.2.35 is not affected by CVE-2026-64649. The upstream vendor (Vercel/Next.js) introduced the __NEXT_PRIVATE_ORIGIN protection mechanism in version 14.2.0, which is present in this target. When using the framework's standard production mode (next start), this environment variable is automatically set, preventing the SSRF vulnerability by using a predefined origin instead of untr..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a8e234d-ebab-5ee4-b325-e2f0da91b64e",
      "id": "GHSA-8h8q-6873-q5fj",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8h8q-6873-q5fj is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca7a2dd6-00f8-522a-8f68-f5df4bfc5a66",
      "id": "GHSA-h25m-26qc-wcjf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h25m-26qc-wcjf affects version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ed1c354-f9df-5d0f-893c-0516bc944b7f",
      "id": "GHSA-q4gf-8mx6-v5v3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q4gf-8mx6-v5v3 is fixed in version 14.2.35-tuxcare.4 of @next/react-refresh-utils."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40next/react-refresh-utils@14.2.35-tuxcare.4"
    }
  ]
}