{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:174375d1-ff4b-51f8-944c-8927ca826945",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3",
      "type": "library",
      "name": "@nuxt/vite-builder",
      "version": "3.2.0-tuxcare.3",
      "purl": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b8b8dd9d-a4d6-580e-82fe-1bce9e9b7624",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a52403-efb9-5525-b20f-effa401be7f5",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1b8c34-efc0-5b38-9c78-f474f1557107",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52788e8a-fef6-5720-af29-c5a3d526b39e",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4cef753-508b-5acf-9702-3319379e7334",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76609f5f-29a3-50cc-b941-05b2d9ef903d",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9e6e7f4-b872-5e5f-ac50-5f71b88de4f3",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d607244-8e6d-5c9b-a383-306adb1be7d1",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d1ff30-e566-5f8d-81d5-f878483f16a5",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce564319-4dd8-5f64-ad13-d82150db1283",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb09178b-546e-55e5-8318-73fece951801",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a60327d-a592-5bbb-9c50-2cc82f3e3a56",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05103289-58e0-5f39-b156-92a279ce4cb2",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e6546d-a988-527c-a654-091e58864a26",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2283d27b-e813-54bb-98cd-23455578d120",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b26163b4-602a-5ac3-a165-261fa310ac44",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:798b967b-0169-5ec9-937b-c378edab58e7",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3d5bf38-5e3a-50a6-b23f-252012bfea9d",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed462d9e-0f9d-5c4f-bf8a-99842ba8628a",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a47f94-a511-5e64-b49a-d5c0b979651b",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173b5279-eb3a-5bb9-ae8f-2c323b7e6db7",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26263b44-302f-523c-b5f4-9f3a3a66f9f0",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab9bb10a-5f13-5dbf-82a1-858131ec59c0",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d87549d-3d4e-5313-a876-67303da565e8",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.3. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1826e69e-cdb3-51ab-b4fe-3de2ad65a62c",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1daccf55-6fb7-574e-9a8e-54acbd62e72e",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86a12b31-ff9c-5090-99d8-63a49310dc03",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.3 of @nuxt/vite-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bbfad2c-761b-5bbb-bbd4-b420f760f9b7",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a687bd9b-9311-5f08-9503-a1d486a0b9a2",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.3 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d10988f-a436-5b47-b3f6-c8c9aa37f8ff",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.3 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4ffd7da-6141-5ae7-89b9-a104bf10bae3",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.3 of @nuxt/vite-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:645d7ba3-a9ef-5db9-9f91-6c304d6aada5",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.3 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.3"
    }
  ]
}