{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a60a3b49-ac1d-56e0-9391-63a92dba1b89",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.7.9-tuxcare.1",
      "type": "library",
      "name": "axios",
      "version": "1.7.9-tuxcare.1",
      "purl": "pkg:npm/axios@1.7.9-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e1d69dd6-bb68-5ecd-9f34-024d3d79c56a",
      "id": "CVE-2020-7676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7676 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e673a206-34c0-5b1f-a99a-0704218e6db3",
      "id": "CVE-2022-25844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25844 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb98be97-dd27-5574-92fe-ab8048e5400a",
      "id": "CVE-2022-25869",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25869 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ece4a290-fc06-5ac4-9b5a-e253a024821b",
      "id": "CVE-2023-26116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26116 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e7c650-e93a-51b2-8543-ebaece59a5c9",
      "id": "CVE-2023-26117",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26117 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36405fea-ca0d-5b3c-9508-0466952bad0d",
      "id": "CVE-2023-26118",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26118 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09992609-f440-53e2-8bfa-09d1c29dc79f",
      "id": "CVE-2024-21490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21490 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f21625f-8a7e-5e4b-8e6e-bca519f85585",
      "id": "CVE-2024-8372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8372 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10e6e146-d5fa-5e0b-aa70-7d3c9fd4c297",
      "id": "CVE-2024-8373",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8373 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3ccaa49-9777-5792-b57a-893140a0f88e",
      "id": "CVE-2025-0716",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-0716 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13fb8def-471c-5998-911a-bca53a81b018",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5841c9f8-9d81-5b42-bb12-1f3ade0c6c2e",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a94e8b05-30aa-5a1d-88e2-8ecc980651f5",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0b3e8e8-e059-5e12-a97a-b25adbeac2a4",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.7.9-tuxcare.1 of axios. Version 1.7.9 is not vulnerable. Summary: The target repository (axios v1.7.9) is NOT vulnerable to CVE-2026-25639. The target uses Object.assign({}, config1, config2) for key iteration, which does not include __proto__ in Object.keys() results, preventing the DoS crash. The vulnerable code pattern was introduced later in v1.11.0 when the code was refactored to use the spread operator ({...config1, ...config2}). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae3349be-6601-5c88-b4bf-b4ac32d4c334",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70e0ff45-fd4d-530e-8e75-a682ff1ee15e",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea100e2-2b0a-5d08-b704-9470dcf91edc",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77f5db7b-5774-5b48-a8c0-544db91f08d3",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1189c473-ae8e-57fb-aeea-4c5ff8de2306",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d73f15-c6ec-5263-afe9-844da5c9f40f",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbd3a78-cf26-5f4e-a560-e488623ee83f",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf3dcb73-9885-52eb-bbb8-a260e3cacf47",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3e293df-513c-5f15-9644-8e4a1cc5e06c",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:251c551b-99b1-5759-a8d6-254afdd2eefd",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03087898-92b9-51cb-ba32-d8059e14c73a",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed9b101e-ef8b-5098-bfe8-b9ab99d5fdf2",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.7.9-tuxcare.1 of axios. Version 1.7.9 is not vulnerable. Summary: The target version (axios v1.7.9) is NOT vulnerable to CVE-2026-42043 because the vulnerable shouldBypassProxy feature does not exist in this version. The target uses the external 'proxy-from-env' package for proxy handling, whereas the vulnerability exists in axios's own shouldBypassProxy implementation that was only introduced in version 1.15.0. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b904aa6-3af6-5de3-b5a1-452e0c785c8f",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc71edef-666a-508e-96ab-6436f20a7657",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aadbacf0-c41d-5b6c-a7e2-aac772be8c68",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6341b57-9e77-5657-bd24-4437bd9079a1",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec73d5c-fc6b-5fcb-be35-0087829c057c",
      "id": "CVE-2026-44488",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44488 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c97a9b3-36fb-56b8-9c2e-fdab31c8aee7",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bacf240f-349b-5072-9712-cfdcc9cbf6d0",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a201d194-2d85-5349-a49f-980cc96ce8c9",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44494 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a02dbc1-95fc-5a1c-9cb1-2e3de9059f45",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5272a52c-791a-596e-a3c9-11905002db77",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5409b4d2-5804-5db7-ba0a-41cd3fb48a8b",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ccf3d9a-fccf-5797-821f-51c3e3fb94df",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:612e6f70-d669-59ef-a09c-193ee988bf32",
      "id": "GHSA-jqh4-m9w3-8hp9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jqh4-m9w3-8hp9 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f9b453-c344-5380-a0ca-920bd8ae7100",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d80e70b5-8640-5031-a9df-fbdd4b83bfb7",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.7.9-tuxcare.1 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.7.9-tuxcare.1"
    }
  ]
}