{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dac63636-0337-507f-b6f5-ab7228dc9ca4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3",
      "type": "library",
      "name": "@nuxt/webpack-builder",
      "version": "3.2.0-tuxcare.3",
      "purl": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5bd330a8-3dca-52a3-a17d-62e3f1f46f5a",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb2ba349-f0a3-5772-a986-dac341abe83f",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4509ea-214a-576b-a39b-769f2141a703",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7a30248-e702-550a-9fac-fc5630b0c104",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fb67c5-3b72-5891-b32f-45a064cbf547",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64e7cb3a-0136-5b3c-9f0e-eaf6a25bf659",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ea32495-3080-51e9-9b05-0dc66a4bbd18",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a654b4c-214d-552d-8d1d-8e424d434373",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c4ff3c2-f878-5f69-96f6-5cffc210673c",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64313ad0-cf7e-5255-baf6-bc8ca0ca0f40",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5563cd85-86e8-521a-a267-b22f23992760",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6cfc83-581a-5c22-8ba9-65a433cc9ebb",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c0bce9-c318-5515-8a18-d31eb603eca4",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aee677f-ed1a-5e8a-bb5f-319f186977b2",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea3753cf-2067-532c-93ce-f52cbef3d6d9",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b0fe570-0684-5d0e-9d5e-f2cb7f2c0649",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241aa58e-cf81-55a3-b99a-addaaed7af54",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc50045-1029-5a96-9d37-4e508f2441aa",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d096359f-2753-5fad-ad28-7aa2555694dc",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd79bc9a-ba74-52bc-829d-3adb818b81e8",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675a354b-80af-5325-ab93-d5a51bf52cfb",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f88fe889-fc08-5ffe-ab1d-841ef9a1be62",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c2e8d38-fff8-57aa-bda2-8896d10f063a",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b69fdfe3-9abc-5030-8f5b-b0457ed48e78",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.3. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:877764f1-2ba9-5c8b-8924-98651bd20533",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:676bcdff-4547-5406-8bd6-2a2fc20259ab",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f7ad00-6e78-5eb0-9260-efede3c3f5de",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.3 of @nuxt/webpack-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062253e3-cd90-5cc5-9840-657d397657b9",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a6b897-a044-5b7e-b0c7-1200973ba455",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.3 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9d5b1e-bb4b-58aa-9798-1055f595e2cb",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.3 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:138db3c3-6707-5fe7-b998-17102c3a9ca2",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.3 of @nuxt/webpack-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f1b6d0-c301-5779-b7b2-4b18d6944903",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.3 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.3"
    }
  ]
}