{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6d1eb971-a7a7-5538-bbe4-4db9c0784348",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/handlebars@1.3.0-tuxcare.3",
      "type": "library",
      "name": "handlebars",
      "version": "1.3.0-tuxcare.3",
      "purl": "pkg:npm/handlebars@1.3.0-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3a70de5c-a3bf-51b7-93d8-864f1065682d",
      "id": "CVE-2015-8861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8861 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23c45d69-0a1c-501f-9929-e7cde4fff6c8",
      "id": "CVE-2017-16138",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16138 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebab2fd6-e398-528c-b2fa-4fd861d7027d",
      "id": "CVE-2019-19919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-19919 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61094f0f-7e78-5ed3-94c2-4419d9665c37",
      "id": "CVE-2019-20920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20920 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:818e805b-7359-516d-91a6-e1388f3f2c29",
      "id": "CVE-2021-23369",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23369 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42df015b-fad3-554c-8d96-1ceb5dcef1f8",
      "id": "CVE-2021-23383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23383 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2bd3ce-a183-5cb0-8167-e2726c50cd4e",
      "id": "CVE-2025-32014",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32014 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a6a2118-fbb2-53d9-8314-5cfe92f85404",
      "id": "CVE-2026-33937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33937 affects version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2131c0c-ecef-566a-b194-c12d19390b23",
      "id": "CVE-2026-33938",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33938 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 CVE-2026-33938 describes a vulnerability where the @partial-block special variable can be overwritten with a crafted Handlebars AST via helpers, leading to arbitrary JavaScript execution when {{> @partial-block}} is invoked. The target repository (Handlebars 1.3.0) does not have the @partial-block feature at all, as this was introduced in later versions. The specific attack chain described in t..."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1630a9f3-57e4-5f92-9a7d-78cd8d5004ca",
      "id": "CVE-2026-33939",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33939 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 Handlebars version 1.3.0 is not affected by CVE-2026-33939. The vulnerability concerns decorator invocations ({{*name}} syntax), but decorators were not introduced until Handlebars 3.x+ (2015-2016), years after version 1.3.0's release in January 2014. The target codebase has no decorator support infrastructure: no DecoratorNode in the AST, no decorator visitor methods in the compiler, no decora..."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25d8c531-b385-5613-909b-c79ce6adfe65",
      "id": "CVE-2026-33940",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33940 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 Handlebars 1.3.0 is not affected by CVE-2026-33940. The vulnerability requires dynamic partial support ({{> (expression)}}) which was added in v3.0.0+. Version 1.3.0 additionally employs constructor validation that rejects plain JavaScript objects from being treated as AST, blocking the typical attack vector where user-controlled JSON data reaches the compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3231513-5d09-5a57-8d75-61e67be4a06d",
      "id": "CVE-2026-33941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33941 affects version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8781d1f1-c539-5335-955c-27cfd42d9661",
      "id": "GHSA-2cf5-4w76-r9qv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-2cf5-4w76-r9qv is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737aa0ca-759f-5ba4-ba00-17f12130c144",
      "id": "GHSA-442j-39wm-28r2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 1.3.0-tuxcare.3 of handlebars. not_affected \u2014 Handlebars version 1.3.0 is not affected by GHSA-442j-39wm-28r2. The vulnerability exists in the container.lookup() function when compat mode is enabled, but this function and compat mode were introduced 7.5 months after v1.3.0 was released. Version 1.3.0 uses a fundamentally different architecture for depth-based template context handling."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e2b5f8-0490-5735-8621-da1989c1de58",
      "id": "GHSA-6r5x-hmgg-7h53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r5x-hmgg-7h53 is a false positive for handlebars 1.3.0-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f446af-c1a0-5268-bfd7-b912a4b4f12c",
      "id": "GHSA-7rx3-28cr-v5wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d362e43-1e42-5796-a108-8b6adf540818",
      "id": "GHSA-fmr4-7g9q-7hc7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fmr4-7g9q-7hc7 is a false positive for handlebars 1.3.0-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e6177a-9598-5e40-b75e-2313f411f572",
      "id": "GHSA-g9r4-xpmj-mj65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-g9r4-xpmj-mj65 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd69c0a-0f7d-5df7-945d-c37912ec503e",
      "id": "GHSA-q2c6-c6pm-g3gh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q2c6-c6pm-g3gh is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70bce7c7-be96-520e-850e-80e40c229d6d",
      "id": "GHSA-q42p-pg8m-cqh6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q42p-pg8m-cqh6 is fixed in version 1.3.0-tuxcare.3 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/handlebars@1.3.0-tuxcare.3"
    }
  ]
}