{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9e9103c7-529b-59e9-a6e2-78e97f78b487",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2",
      "type": "library",
      "name": "@nuxt/kit",
      "version": "3.2.0-tuxcare.2",
      "purl": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cfd10930-ea40-5425-a4bb-bd3139b845e4",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbff4ac7-6485-5047-94e2-d7d66a4ed933",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab903e05-c8ef-5a80-bbc9-c0a21b866705",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6b32e86-e6bd-5616-b745-5bf69c84b530",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3ea04e-f23a-5394-8667-ffd8480297a7",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7190846-4b71-5c8a-a8d9-66b1c72015af",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b62fef63-90de-57a4-b629-744096185170",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b7cd395-c090-5ff6-b907-6b6c4e9d6f7b",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2d931eb-bee0-5c78-a851-eabb6c997478",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85c7ef4e-7978-5ea5-be13-6d9a77724ec8",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2b72dbe-3744-599f-9f71-719bdb6445eb",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc850745-43f2-5415-9861-c09124ab341f",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61790a7-0dd1-5036-9d50-b1bcc40afe9d",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58078bb3-3c19-5707-afc3-65636fc69e6c",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4322bb5-f67b-5e26-9889-0ca1289e0a5c",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:598e5ec7-5a83-58f7-b041-931488810b25",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adad994-cbea-5a55-a9c2-9d2ff7f606aa",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:676b6394-0cdd-5f02-b0f8-cb25ab7e6d42",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e53b2bdf-ae88-5634-b438-cd9622820610",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24afa1bf-2ab9-5f09-8a76-7695884959cb",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bc4ced3-e33e-53ab-9094-c4ba639ce675",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c92216cc-4405-5970-9ea7-dc414c630bcd",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6abbe22f-1e32-592f-a47e-25f11353da6e",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b011752c-2b0d-5e54-a5ec-d8e21575ce35",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/kit 3.2.0-tuxcare.2. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907c25d0-4d80-5910-a17d-a79e3319e194",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c548583-2e99-504c-8697-a98ace0d23d1",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96e5079d-47c2-5e01-b017-29f848bc4fc1",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.2 of @nuxt/kit. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c3cba30-5303-5759-bfef-2947337e18f8",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20d37505-b181-5526-afd2-5ed2a2b8daa1",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.2 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4afb2f9f-4069-5de2-ab8f-4113ce39c4b9",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.2 of @nuxt/kit. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f59cca0-738d-5dbc-bae0-69e49e09199a",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.2 of @nuxt/kit. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29b2bec0-fe82-595c-b138-4c347957795d",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.2 of @nuxt/kit. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.2"
    }
  ]
}