{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:78782927-39d2-5bdd-90ac-716a0b056263",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3",
      "type": "library",
      "name": "@nuxt/kit",
      "version": "3.2.0-tuxcare.3",
      "purl": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0a505dc9-df46-5be4-acce-1ddc910ecdb1",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c18494-d6b9-56f1-8f6e-60f1a3f597a3",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60b85f67-ef4a-51f2-8f33-9a931c89e6fe",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fcad959-ff8e-5ece-88b8-8c8c0980d2e3",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffadaf0d-d910-564f-9ed4-7b32ce7ecdc4",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a13347-721c-5afd-abfd-06dc6e52d290",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5b17110-3847-5bfc-954e-3a3ee4fe2b1a",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbad500e-c006-577f-bdc1-49f942ba5d95",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c8d4bc3-0d1c-5b56-8c36-cb23ecc8415f",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9da6422-0c99-56ea-b82b-d6e81c83576d",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3c9970-2690-56a3-9796-8ddb7e72d595",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bcd6e40-40e3-5e86-b484-90d66c1836e0",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edaf029f-4a6e-5b9d-b48c-5af2d50e6539",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b562da68-7ab2-5c6d-87c3-eb2b277e2ba0",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b528d951-3093-54fd-9b9f-6199ac99383c",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f20b0336-252b-51e4-ad55-39ebb89e631f",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce5ae7c2-70b8-5026-854a-22eb7dfd888f",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc355585-307c-5ca2-bf87-d15f46aaedf4",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f724f61-4000-543d-922b-93cd94c00458",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a797e8d4-035b-5c3b-802f-845914225acf",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544c0527-28a2-5c20-998f-f8e21dace342",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dec87a89-239b-5626-991e-42ccdca968a9",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dfa6d40-63de-5963-a41e-b7d14de31719",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97ae522b-4c1c-5ac4-a8c1-9ae016e022cd",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/kit 3.2.0-tuxcare.3. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:216ce806-1a90-544e-a314-36e8e2174fd9",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cc9f637-abb4-57e4-bc0c-97e44295bf71",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acfd9cb9-1247-5d03-87ad-4a6f572bd0c5",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.3 of @nuxt/kit. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feadc31b-2004-523e-865b-26b2714f8053",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa35b8e2-e51c-5f60-a1a2-b428bf263cc9",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.3 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ef412d5-5428-558b-8ee2-57828fcbba88",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.3 of @nuxt/kit. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c4e400-8e76-5c4e-b6aa-fd19c6dada3f",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.3 of @nuxt/kit. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9807ff50-6bf7-50a8-a51a-8f1a6f2e1ee3",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.3 of @nuxt/kit. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/kit@3.2.0-tuxcare.3"
    }
  ]
}