{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:47dc8013-931f-53da-b166-63a1f9b5330f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/handlebars@2.0.0-tuxcare.1",
      "type": "library",
      "name": "handlebars",
      "version": "2.0.0-tuxcare.1",
      "purl": "pkg:npm/handlebars@2.0.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d146ae76-beb0-5409-8cc7-8136ae16ba83",
      "id": "CVE-2015-8861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8861 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da250883-f72d-5835-a657-b993361523a3",
      "id": "CVE-2017-18214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-18214 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d9c66f-dce8-59ff-9a03-bb5e81c7a995",
      "id": "CVE-2017-20162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20162 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:025f5864-a074-53b8-b9cf-f3d283acc0aa",
      "id": "CVE-2019-10747",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10747 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfc7d461-8708-5035-bf6e-bdbad63beae2",
      "id": "CVE-2019-19919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19919 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6efdbcab-9b83-5a31-ab7a-fa1c930ec5a8",
      "id": "CVE-2019-20920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-20920 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94940e94-67c2-5879-97e5-2dc83c48e771",
      "id": "CVE-2021-23369",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-23369 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e2364a4-7a2a-5193-8fea-41e745bb1ba2",
      "id": "CVE-2021-23383",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-23383 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f0aef0b-fbb5-58a6-83e9-bca7de684ed6",
      "id": "CVE-2021-23440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23440 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f881fb-3410-56e3-a918-e96e719c0458",
      "id": "CVE-2021-23807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23807 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:876079b0-a963-5fd2-a038-aea4baf7cb8b",
      "id": "CVE-2021-33623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33623 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87d1c42c-4972-5c97-87b9-52aa1d6dcb4d",
      "id": "CVE-2022-24785",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24785 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:408d9254-22e0-535c-b429-2fa57fc70c22",
      "id": "CVE-2022-37599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-37599 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0aecbfa-879a-5377-87a4-c17b6a2b93ef",
      "id": "CVE-2022-37601",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-37601 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ec3a30-a851-5df8-a382-657f67feb4c8",
      "id": "CVE-2022-37603",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-37603 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3167577f-7a95-5d7b-9e59-c35565e71287",
      "id": "CVE-2023-42282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42282 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205e7f69-55b4-51ee-88a7-4e7f26f4ff59",
      "id": "CVE-2025-7783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-7783 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9bbf40f-55e0-58fb-b96c-1e182c4856d6",
      "id": "CVE-2026-33937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33937 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc0f71a-e217-59d5-91fa-4bb5a3b6e8b8",
      "id": "CVE-2026-33938",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33938 does not affect version 2.0.0-tuxcare.1 of handlebars. Version 2.0.0 is not vulnerable. Summary: The target repository (Handlebars v2.0.0-tuxcare.4) is NOT vulnerable to CVE-2026-33938 because the @partial-block feature and associated vulnerable code do not exist in this version. The vulnerability only affects versions 4.0.0 through 4.7.8. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b801ccb1-5126-5790-ad63-e70cbb2b623d",
      "id": "CVE-2026-33939",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33939 does not affect version 2.0.0-tuxcare.1 of handlebars. Version 2.0.0 is not vulnerable. Summary: The target repository (Handlebars 2.0.0-tuxcare.4) is NOT vulnerable to CVE-2026-33939. The vulnerability affects Handlebars versions 4.0.0 through 4.7.8, but the target is version 2.0.0, which predates the introduction of decorator support. The vulnerable feature (decorator syntax {{*name}}) does not exist in this version, therefore the vulnerability cannot be present. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7ec332b-5593-5659-a7b9-0ab987870def",
      "id": "CVE-2026-33940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33940 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0644a5-99cc-536f-93bc-201e46f457ce",
      "id": "CVE-2026-33941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33941 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530b690c-ee21-579f-89cf-6d3117b2d891",
      "id": "CVE-2026-3449",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3449 is fixed in version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dfba8d2-cf35-550a-80a4-c54067a5e977",
      "id": "GHSA-2cf5-4w76-r9qv",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2cf5-4w76-r9qv affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3839d5c-ab96-5a69-85c0-0627efff6a50",
      "id": "GHSA-442j-39wm-28r2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 2.0.0-tuxcare.1 of handlebars. Version 2.0.0 is not vulnerable. Summary: GHSA-442j-39wm-28r2 TOCTOU vulnerability has been fixed in this target repository. The container.lookup() function now properly returns the validated result from Utils.lookupProperty() instead of performing an unguarded property access. The fix was applied in commit dcfe4311 on 2026-02-18. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d4e61a5-ee6c-5b24-862a-39bfe04e54bb",
      "id": "GHSA-6r5x-hmgg-7h53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r5x-hmgg-7h53 is a false positive for handlebars 2.0.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f1912fd-76ce-53d1-ac15-51619a23436c",
      "id": "GHSA-7rx3-28cr-v5wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c98bd7-6dc1-51ff-be74-47e8d951f15c",
      "id": "GHSA-fmr4-7g9q-7hc7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fmr4-7g9q-7hc7 is a false positive for handlebars 2.0.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:212781eb-5ac3-541a-b434-f55400479838",
      "id": "GHSA-g9r4-xpmj-mj65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g9r4-xpmj-mj65 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21e0bbda-60be-5b0c-979c-000bc04de4b3",
      "id": "GHSA-q2c6-c6pm-g3gh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-q2c6-c6pm-g3gh affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b24bf99-3650-5816-ad2c-ad050f7149a1",
      "id": "GHSA-q42p-pg8m-cqh6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-q42p-pg8m-cqh6 affects version 2.0.0-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/handlebars@2.0.0-tuxcare.1"
    }
  ]
}