{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:96a83056-a2ae-57be-8eb0-c06cb92ed88b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4",
      "type": "library",
      "name": "@nuxt/vite-builder",
      "version": "3.2.0-tuxcare.4",
      "purl": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4af16153-608b-5623-9e78-35b4efbb2fb5",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bad1a2f-d8b3-55be-bee1-9562c2abffd2",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9c34f27-b216-52fb-9470-71ce71e68a4a",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd417b13-dd11-523a-a9e5-3706899ea963",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95ea84aa-ad2f-5dce-81e6-cd800c98adbd",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:921827d7-07d0-5fb9-883e-712471c0bc27",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48aeb46-30cb-5e4b-8f37-d31c7a388a02",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4b648e9-3794-5122-88ed-9150177c9016",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb6d34f-2b9f-5f23-897a-b87c068564f4",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d966c9b3-390d-5cd6-a5f5-6a5121bd530e",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78acb13c-3a65-5154-b630-f6ac07182fd4",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b67181c-6ce5-5779-b337-c64297f0d63e",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46653961-d958-51bd-80ae-f3bdaa31976f",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:300a40d4-f39b-53da-9db0-31e801569782",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2308b9-8079-56d3-84df-873f6c80599e",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a374473f-394e-50ec-90e2-fdad45dfd4c7",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4151338b-72ad-5a83-b931-aa0ea922a96d",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9c0fa0b-7e2a-5213-ad1d-a0bccf34dd91",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6049df74-0013-56c2-b15c-a31842e30396",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:823f374f-786d-5d8f-acc0-f56f0d123d72",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e28e9321-ff24-5816-a69d-e46a773416f6",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89706741-aa59-5c30-b41c-6ab6677fc5c6",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf993be3-fb88-5bdb-aa8a-0e3ea1219e97",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c64553d4-c30c-5173-9c53-04f1efdb12fe",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.4. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70553b87-ede3-5d53-86a9-c5d97b553d4c",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d6e773-e915-535e-b4cc-2531514e9fff",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c7edd3-a832-58b1-9047-a4e43b3b407a",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.4 of @nuxt/vite-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e3ebef-2079-5219-87cd-f707832a33ec",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7521e38a-684d-5170-9d02-f9e64705a807",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.4 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f21ef9-4954-5a60-b39c-97216dd61e38",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.4 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45adb0c9-572a-5de4-96e4-9b3fd40e73f0",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.4 of @nuxt/vite-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32b8a46-d940-5a38-8bec-ab4c2769c5f9",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.4 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.4"
    }
  ]
}