{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9b5d52dd-e5ba-5c5e-95ed-827afc6d5389",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/handlebars@1.3.0-tuxcare.2",
      "type": "library",
      "name": "handlebars",
      "version": "1.3.0-tuxcare.2",
      "purl": "pkg:npm/handlebars@1.3.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b2cdb246-d8f0-5cea-813c-44ab845b409a",
      "id": "CVE-2015-8861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8861 affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c4cbdb4-f055-5043-a2d5-416da991c685",
      "id": "CVE-2017-16138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16138 is fixed in version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aef40b3a-aff5-5f22-bd0e-d3fd55b98f11",
      "id": "CVE-2019-19919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-19919 is fixed in version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47f76e46-4d7b-5687-bbe3-af72a195add8",
      "id": "CVE-2019-20920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-20920 affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b20200b-0a4b-5a89-b63b-55dc95564925",
      "id": "CVE-2021-23369",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-23369 affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01774088-d5b5-5a46-abc0-ac7f93a4dbb5",
      "id": "CVE-2021-23383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23383 is fixed in version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e2b924-8408-5d6a-acba-282884ab66c7",
      "id": "CVE-2025-32014",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32014 is fixed in version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf4dade1-44c1-55f6-959a-efe59e4d1efb",
      "id": "CVE-2026-33937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33937 affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24725b20-43b2-533e-abf5-733b34512c91",
      "id": "CVE-2026-33938",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33938 does not affect version 1.3.0-tuxcare.2 of handlebars. not_affected \u2014 CVE-2026-33938 describes a vulnerability where the @partial-block special variable can be overwritten with a crafted Handlebars AST via helpers, leading to arbitrary JavaScript execution when {{> @partial-block}} is invoked. The target repository (Handlebars 1.3.0) does not have the @partial-block feature at all, as this was introduced in later versions. The specific attack chain described in t..."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58805c6d-0348-52a1-8989-aac2b7396dc0",
      "id": "CVE-2026-33939",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33939 does not affect version 1.3.0-tuxcare.2 of handlebars. not_affected \u2014 Handlebars version 1.3.0 is not affected by CVE-2026-33939. The vulnerability concerns decorator invocations ({{*name}} syntax), but decorators were not introduced until Handlebars 3.x+ (2015-2016), years after version 1.3.0's release in January 2014. The target codebase has no decorator support infrastructure: no DecoratorNode in the AST, no decorator visitor methods in the compiler, no decora..."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5592ef3-fb4f-58d6-b36a-b201dae5e782",
      "id": "CVE-2026-33940",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33940 does not affect version 1.3.0-tuxcare.2 of handlebars. not_affected \u2014 Handlebars 1.3.0 is not affected by CVE-2026-33940. The vulnerability requires dynamic partial support ({{> (expression)}}) which was added in v3.0.0+. Version 1.3.0 additionally employs constructor validation that rejects plain JavaScript objects from being treated as AST, blocking the typical attack vector where user-controlled JSON data reaches the compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b684593-ffad-5a9b-aca7-d2107146efe4",
      "id": "CVE-2026-33941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33941 affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adc0feb1-3f92-5d4e-94d7-ea9270ad9c19",
      "id": "GHSA-2cf5-4w76-r9qv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2cf5-4w76-r9qv affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81f9181-2129-5882-ab86-ed4c3ad410e4",
      "id": "GHSA-442j-39wm-28r2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 1.3.0-tuxcare.2 of handlebars. not_affected \u2014 Handlebars version 1.3.0 is not affected by GHSA-442j-39wm-28r2. The vulnerability exists in the container.lookup() function when compat mode is enabled, but this function and compat mode were introduced 7.5 months after v1.3.0 was released. Version 1.3.0 uses a fundamentally different architecture for depth-based template context handling."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c9f2f0-5696-5cad-be30-d1b5d4411ff2",
      "id": "GHSA-6r5x-hmgg-7h53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r5x-hmgg-7h53 is a false positive for handlebars 1.3.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a97cb8d1-ef37-505b-85c8-97f92bc87f2d",
      "id": "GHSA-7rx3-28cr-v5wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b0309b-99fe-50af-a084-42004ee12347",
      "id": "GHSA-fmr4-7g9q-7hc7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fmr4-7g9q-7hc7 is a false positive for handlebars 1.3.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a60c4365-0160-5175-8297-f456b3aa940b",
      "id": "GHSA-g9r4-xpmj-mj65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g9r4-xpmj-mj65 affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9140024a-646e-52cc-ab7d-313877b6a768",
      "id": "GHSA-q2c6-c6pm-g3gh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-q2c6-c6pm-g3gh affects version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:389b0bf1-e4c5-5f34-8d31-de3756197487",
      "id": "GHSA-q42p-pg8m-cqh6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q42p-pg8m-cqh6 is fixed in version 1.3.0-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/handlebars@1.3.0-tuxcare.2"
    }
  ]
}