{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:db55e1db-05cc-572f-8218-c5fea9b8e4e0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.18.1-tuxcare.3",
      "type": "library",
      "name": "axios",
      "version": "0.18.1-tuxcare.3",
      "purl": "pkg:npm/axios@0.18.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9f3995b1-6aa7-5e04-973c-f365f9a64a71",
      "id": "CVE-2020-28168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28168 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d76af30-60bf-5b08-9b9d-09b52a540974",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:470d4f1f-2ef3-5533-827a-90999d31c16d",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b46a760a-d173-5b26-88ef-196d374ea4c6",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39338 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1634956-8fd0-59ee-a591-c797b5e220d7",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a269f4-9359-5116-811b-286f31301b8f",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d69739-7dc8-5b8e-bf74-cbe3a4c52775",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cca3881-26e4-51b5-b427-269ac0b8dece",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2a9e9c2-d547-5b79-97b8-0eb5cff962d2",
      "id": "CVE-2026-39865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39865 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:477ffee0-44d1-54c6-bb6d-2bb1e09b885f",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83431453-aa4a-5d12-9d09-6074991d41c8",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aa5fc94-b291-5510-a1ef-39cbff7c8d3e",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd896378-3281-5813-898b-d5429adbbbaa",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adff61d-b25c-5733-b8f3-9a711f19d7c9",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d8cd8f-a00d-5eb0-a94c-315fb1af095b",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec06b1b2-6d8f-59d6-aeae-a611a0c5499c",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e217fbba-ccb8-51f3-8476-359221e2b384",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7906525-2f4a-517f-b5b9-76b74625ed39",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b58f89d-2b62-5017-9d7e-b3a909042cd1",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ad45639-c14f-5a20-ab0f-85bb84da1779",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c126c6-580c-5b64-9906-758114fbaa1e",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44486 does not affect version 0.18.1-tuxcare.3 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44486 (Proxy-Authorization header leak on redirect). The fix was backported in commit 806a27b (also 3a086d9 in a backport branch), which implements the exact same defense as vendor commit afca61a070728e717203c2bc21e7b589b59b858b."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99327bf5-622e-5e45-ae5b-ba4afcefcd6e",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44487 does not affect version 0.18.1-tuxcare.3 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44487 (GHSA-j5f8-grm9-p9fc). The exact vendor commit afca61a070728e717203c2bc21e7b589b59b858b was backported in commit 806a27b as part of CVE-2024-28849 remediation on April 28, 2026. The defense mechanism strips stale Proxy-Authorization headers on redirect re-invocations, preventing credential leakage to unintended recipients."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26efa53a-9b71-59ce-88e6-dcb5ed5dad5b",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635d1647-726f-5bc5-ae71-6ed3b3ec2951",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 0.18.1-tuxcare.3 of axios. not_affected \u2014 The target repository axios v0.18.1-tuxcare.2 does not implement NO_PROXY functionality at all. The vulnerability CVE-2026-44492 is specific to shouldBypassProxy.js (introduced in v1.15.0) which handles NO_PROXY hostname comparison. Since v0.18.1 predates this feature and has no hostname comparison or bypass logic, the vulnerability pattern cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b377dd73-c96b-5184-9c9a-fd025409c57a",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98816162-01e2-5987-8b49-0191b82e9f8a",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22783d49-1282-52cc-b3b8-f519d62ff7ea",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.18.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.18.1-tuxcare.3"
    }
  ]
}