{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7c5c3eed-2036-5010-9afd-1f1a86899e75",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1",
      "type": "library",
      "name": "@nuxt/webpack-builder",
      "version": "3.2.0-tuxcare.1",
      "purl": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5ef1577c-5047-52c0-b74d-e10224d4e88a",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec6b655-db10-5509-933f-5fd7338ccb2b",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8182f86b-5de7-585f-a30e-975c82e6615e",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9102cb3-bb5b-5b78-bc05-fafc3ad22755",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb237af5-568c-557e-8ab3-1073ee75f6fe",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a027675-7e7f-5df0-b033-0f7660f45c55",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10546f82-7f29-541b-9275-e5255e23c001",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a09093c-61e7-53ce-a3b4-ce22937e059a",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce9aad5-4c32-59f6-959a-a0d62cdc8659",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d714a19-9422-5d92-a48f-0b3e22cd304a",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a22a0b53-4392-5e4a-8c32-352f38ec8466",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8d4120-5d46-5db9-9b39-22c5bc193628",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-8203 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68139982-06f4-5af2-92aa-7c4371f6fda7",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cbb0c42-d23f-5707-bb2c-7693daf350ae",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e21dfaa9-94ba-56cd-8f46-509693a32bca",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4daa838-74f2-5aee-92df-62ea201f6a05",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c56a407-a102-5dcf-8a9c-dfaa23a38677",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f553f5fe-1485-53ef-911c-50b5b6b541f8",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a55532d0-ed58-58bb-bfe0-2fb81561666c",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7003b7f7-1cde-5816-a9e4-66b06f5edb50",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:facd53ec-7eda-554c-8fac-eaa366dc0faf",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b5505bd-3a8e-5abf-b4ab-e7fe7a6a7142",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33151 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db6787e6-8987-5d80-b359-e6b53531b112",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:457c6761-36ac-548e-bc84-b96d1f0d67d4",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.1. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:541bdc74-1538-5185-b8fc-10ac17850b50",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ee53589-0201-5442-9296-5cd82915831c",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70c0f6ba-5dc8-5fb1-a5c6-6a10a76c8458",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.1 of @nuxt/webpack-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0a92ac-d1d0-55c7-87a6-8640396d5408",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a52b1898-d673-52b7-a34e-dfb1c09e0cdc",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.1 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3cd2fc-5e0f-529b-bf91-29056125824d",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.1 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42b634e8-e374-5b2b-a00c-76238718a2d2",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.1 of @nuxt/webpack-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a27bb76-f683-507b-b634-bd3671ca7eb1",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.1 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.1"
    }
  ]
}