{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c4d5c039-cb5a-509a-a000-d5cf6d69fc40",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2",
      "type": "library",
      "name": "@nuxt/webpack-builder",
      "version": "3.2.0-tuxcare.2",
      "purl": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b69b660d-6639-5377-9cf8-e50c38575731",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9ad396-6690-5f14-a3d3-944678bcd898",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a25cde-d025-56cc-8d24-79d9a727af3b",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:520b0a70-3141-5ad8-827b-17ba9057ef2f",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4696cbfc-0327-59e7-80af-5f32d833f15f",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5db4f9a-31e2-50bc-9c0b-ce7da5b29145",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc38357-fa46-5246-9cad-beabd30431cf",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f99da95-5a99-54ac-b3a5-7ed5a006d12a",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c63079-7464-5d14-9ee9-d70d479740a6",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad88f8d6-5e74-5967-b24d-0b6e568f8b3d",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f87df8-5432-586b-bf76-867f4e6ef522",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c87d1a4e-bc1b-58c2-9d41-599ac0641767",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01accb37-618e-58e7-9e25-74b700150782",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61c5ab4b-cae3-5f48-bead-fb289b63f072",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab465fb8-2c8f-57ad-9b71-f7603b490923",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:423a9911-c386-579a-9f66-9592fe0b719b",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a054c2c1-ba95-57a3-bcd7-ddcc7ea6a418",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03542a9a-45d3-5c86-b82c-a9783a084736",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15916ee6-5a75-514a-8b3f-3cc4c0b54574",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8832e1ae-5678-5294-8a9a-368bb2a67260",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8eb6e97-f0c0-507e-aca4-760f9e9e852e",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8613d5-e775-5a84-a3f9-9aee97ea9bdf",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f47b2545-7fed-5955-a9af-2db9396c5c5e",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:678ddd47-c25f-5f23-9422-db4d6386b873",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.2. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67acc1ed-b54b-5c0a-8015-7c949aff2a7d",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6315b02-0608-5f63-9314-92040877be89",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63635f60-7276-58b8-bcd9-6cd5a7343e27",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.2 of @nuxt/webpack-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54147fcb-b5e5-5344-ae34-2b9a53a6a516",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c922de3e-8da2-5253-a0c3-db5363fe998d",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67b3f9c-c674-50ae-9c25-5d6a32237afb",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.2 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04257dcb-d089-53b7-97e7-f65034e0e439",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.2 of @nuxt/webpack-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f0a2bd0-b40a-59f9-ad9b-eae25b18f22d",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.2 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.2"
    }
  ]
}