{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:01a40f1e-befe-5e73-b4ae-d7e6915fb780",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.21.1-tuxcare.2",
      "type": "library",
      "name": "axios",
      "version": "0.21.1-tuxcare.2",
      "purl": "pkg:npm/axios@0.21.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a2f82b6b-1289-5feb-bdca-d4c960f68a69",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f28d775-54c2-5130-97c2-df1aceaaa4bd",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf4c6d28-1373-53b5-ad8e-8ceb55c8c6b9",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.21.1-tuxcare.2 of axios. already_fixed \u2014 The target axios 0.21.1-tuxcare.1 already contains equivalent defense logic against CVE-2024-39338 (protocol-relative URL SSRF) through the 'allowAbsoluteUrls' parameter added in CVE-2025-27152 backport (commit bc6d5a0b). When set to false, this parameter forces baseURL concatenation for protocol-relative URLs, preventing SSRF. The defense code exists in the codebase and is reachable on all exe..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd3832ae-2942-55f9-bdee-870b31c2f4bb",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bef8878e-81d8-5640-a851-46600a0a1727",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6a1bc97-75ca-5733-b23b-51301a8f8ad5",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26d8e5d4-adc7-506c-a087-d26a6fa932ab",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a94b110-2fd1-56db-b933-eb89bc090384",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4382682-2936-5960-8a45-664ad81f1437",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07f77230-e36c-5d7e-9f83-2975baddb190",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b85d480-2c81-539c-b9d5-b041c6489dcb",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:688d36ce-4e23-58be-b00f-927fbcba8603",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1648985-7049-5b72-8741-fac0f6ecf6ff",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63f33aa9-450b-59e2-b46c-3c356f6728dc",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aaa886c-5bfe-5108-9128-93c1b02ec374",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479d1f9a-0573-5ed1-b60e-4e00de3f6c6d",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f1a0869-3264-50d4-a37d-69ece6e47936",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42043 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:587130b1-b2e3-5b89-a650-5dff8f2c8753",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96225359-d376-5640-9b95-d65226a4569c",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b137745-1594-5694-a814-1874cdb15b5b",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4d6401-19de-5b67-a6c5-933589bbe197",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5bcce0e-750c-5b78-828d-97934e96401a",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8422c6a5-f5cf-5a4a-96e2-ca746e460e1f",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:188558a6-b093-532c-862d-cb6c70b08899",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec9e85d8-14a3-58a1-81e4-5fa55f7332de",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.21.1-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.21.1-tuxcare.2"
    }
  ]
}