{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:acaa142a-6cd0-53f2-908e-eda53dacca67",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/devalue@2.0.1-tuxcare.2",
      "type": "library",
      "name": "devalue",
      "version": "2.0.1-tuxcare.2",
      "purl": "pkg:npm/devalue@2.0.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8023e984-9a44-5681-8fbe-8157b5ccb208",
      "id": "CVE-2020-36632",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36632 is fixed in version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f44b60-98a5-59d9-ab76-c53f0ca0d372",
      "id": "CVE-2025-57820",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-57820 does not affect version 2.0.1-tuxcare.2 of devalue. Version 2.0.1 is not vulnerable. Summary: The target repository (devalue v2.0.1-tuxcare.3) does not contain the vulnerable code path. This version only provides serialization/stringification functionality and lacks the parsing/unflatten functionality that contains the vulnerabilities addressed in CVE-2025-57820. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed9f2207-5701-5763-a972-17610454538d",
      "id": "CVE-2025-5889",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5889 is fixed in version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93225478-2ea7-56c4-97f2-a75a690da4f7",
      "id": "CVE-2026-13149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-13149 is fixed in version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f73f7624-46d2-54f9-9dc5-301c233668d3",
      "id": "CVE-2026-22774",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22774 does not affect version 2.0.1-tuxcare.2 of devalue. Version 2.0.1 is not vulnerable. Summary: The target repository (devalue v2.0.1-tuxcare.3) is NOT vulnerable to CVE-2026-22774. This version predates the introduction of the parse/unflatten functionality where the vulnerability exists. The vulnerable code pattern (TypedArray hydration without ArrayBuffer validation) is not present in this codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c95046b1-01dc-5253-8919-810372bd5435",
      "id": "CVE-2026-30226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-30226 affects version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78fdd663-1dc1-5fc3-bd9e-baee045d9dc2",
      "id": "CVE-2026-33750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33750 is fixed in version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:233bc10d-7aa7-5f08-a45f-6f5a2f247e70",
      "id": "CVE-2026-42570",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42570 does not affect version 2.0.1-tuxcare.2 of devalue. Version 2.0.1 is not vulnerable. Summary: The target repository (devalue v2.0.1-tuxcare.3) does not contain the vulnerable devalue.parse function. The parse functionality was first introduced in v4.0.0 (October 3, 2022), while the target is based on v2.0.1 (November 29, 2019). Version 2.0.1 only provides serialization functionality and predates the introduction of the parse feature by nearly 3 years. Since the vulnerable code pattern was never introduced in this version, the  [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b461052a-9a61-52fe-b314-ccea64cddc6b",
      "id": "GHSA-33hq-fvwr-56pm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-33hq-fvwr-56pm affects version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435c37d6-f880-5e6a-a066-3324836fe282",
      "id": "GHSA-8qm3-746x-r74r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8qm3-746x-r74r affects version 2.0.1-tuxcare.2 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c2b378b-6737-56a7-a9a4-279e629d5179",
      "id": "GHSA-mwv9-gp5h-frr4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mwv9-gp5h-frr4 does not affect version 2.0.1-tuxcare.2 of devalue. Version 2.0.1 is not vulnerable. Summary: The target repository (devalue v2.0.1-tuxcare.3) does NOT contain the vulnerable code. The CVE GHSA-mwv9-gp5h-frr4 affects the `devalue.parse` and `devalue.unflatten` functions, but these functions do not exist in version 2.0.1. They were first introduced in version 4.0.0 (October 2022), which is significantly later than the target version. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/devalue@2.0.1-tuxcare.2"
    }
  ]
}