{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:802dc0a4-31b4-571c-a365-2a69307889d1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2",
      "type": "library",
      "name": "@nuxt/vite-builder",
      "version": "3.2.0-tuxcare.2",
      "purl": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98d9b0dc-e6e4-52d6-91a1-0e60aa0abbce",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a875f443-32fd-5663-ac53-f89a3411ffec",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30e4ca6d-454b-5875-8003-805ca557ff3c",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0f263db-5ea1-5960-8002-1851d8f2a0c8",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9d8904-102c-580a-8f18-49b041b1182b",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acacdb91-98f7-570a-8165-29a2fa952fcd",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f216f8-7b0c-5711-b03a-a416869bd42e",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ba4e1d-432d-5805-8915-1e7148387bdb",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef2f0202-bbbf-5f30-a9a3-ebe2977b26a0",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a528f385-28fe-5e8b-bf51-dafc6fcdb864",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fee9e70d-1a23-5dd8-af66-d903cb0fc6ca",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b63bc16-c3ec-5088-94e3-4bf79fc9681c",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58844095-5e00-5886-b095-258cd8a6f992",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d47e4fef-3c60-52d7-a98c-3cf48dd5daca",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f71ec6-2033-5163-8dbc-c5b8003ff2b1",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c91be78-9e2b-5434-8acb-9ef7eacdbc86",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db9ef60-93c6-58fe-b1bd-9562d488023c",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c0ae51-7d3c-5ea9-ae37-b2c653ac7f5b",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22ae9337-186b-58cb-b896-1d09d093819e",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6acb500-478a-59fd-8b56-a32943089a01",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ade31930-fbd9-5032-aac5-e4ceb40c8878",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:226c53a3-5972-5715-96e7-ba42a0def8b9",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48bf8740-0f4d-534c-ba69-46240f43534f",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8684a85f-a6c0-528a-9523-f08bf746b8aa",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.2. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5441110-4b24-52cd-bbea-1444de2caec1",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3b13fdf-819a-50be-8cdb-07f14af5798e",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aa79916-3cd7-50ce-9f46-631552b67d48",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.2 of @nuxt/vite-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be4c0ecb-f2f6-5885-b379-f1b75c21ad59",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db31dc8b-3906-57df-8371-d10f7b39c82e",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.2 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5b6f99a-d18b-5274-9d13-c1a807a155e6",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.2 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e209d18-7bec-5cef-a970-786b854940e6",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.2 of @nuxt/vite-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea97dffe-becc-5e06-a8ac-17708f7ec186",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.2 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.2"
    }
  ]
}