{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:58b1c334-6550-597c-9691-90ce2512f043",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4",
      "type": "library",
      "name": "@nuxt/webpack-builder",
      "version": "3.2.0-tuxcare.4",
      "purl": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0bd70631-5011-5b28-b1dc-f3f45cfde200",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45c00c4-f8b1-5c80-b361-41697cac03fe",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a8beba-de80-5e4f-b8d9-9d3077bba2b6",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8f44fcc-25f6-5a8a-8041-169c459a45a5",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f737ef49-7915-5472-ba2b-3945ed7f6397",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b25a6ec-a0f1-5693-9215-b064e15eab99",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:949605aa-ab81-52d3-a469-2dd71aafbd97",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc811f77-b138-584c-b9f6-2bd4aa3b1485",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:759ebde0-0725-5988-8266-6249d09ac199",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb85ebf-b222-573a-8e7e-1c7cda667503",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d37044ba-fe5d-5bbc-9b4f-bd40ccaa4ce8",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b68e70d4-0ee0-5e00-ae5f-0f941cbcc5c0",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9644a5a8-ce62-5baf-9df0-d567c946a09b",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b8875a6-aa75-57f1-a415-77474adbf955",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc8de6b7-6dcf-59cf-bd44-42c928b83b9c",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4253df08-4156-5bca-92df-082dbde29cf6",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700faa67-dc64-5762-993c-b45d2b251e1b",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fd4babd-3d41-522b-9b8d-7f3e31bf32c9",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f59941d8-7e0b-570e-be8d-bef8b1bee100",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21cc178a-db50-5b4c-ab07-e6c6051b618a",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18170521-0b6b-5966-9b06-39f95acf2bb1",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d03659a3-1e9f-5a9c-9bc8-65656a82db80",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4f7e555-1a14-50f6-9c3e-6cf3019858b3",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:139f5674-9e7d-57ee-98cc-7adae5b9a902",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/webpack-builder 3.2.0-tuxcare.4. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df870e13-0af9-5168-97a6-c854eceff7ad",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:656872e3-5bc7-5cd9-8745-627528dc1261",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afd080a8-21fd-538e-a76e-b57bbabe1a3d",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.4 of @nuxt/webpack-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5996c35f-cbae-5d9e-b275-93c1082f47e5",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b48167aa-9b47-5caf-98e4-1378162d2e9d",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.2.0-tuxcare.4 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58124aac-5a0d-5bc2-acf2-3b7148e641f2",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.4 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b9c3d3-8ffd-5d84-b39e-e1d7d18e1f43",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.4 of @nuxt/webpack-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4510537a-3406-5b49-b36c-b9dd250df297",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.4 of @nuxt/webpack-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/webpack-builder@3.2.0-tuxcare.4"
    }
  ]
}