{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:82223d6d-fcb3-5606-9322-9510aea0a9d1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/handlebars@3.0.3-tuxcare.1",
      "type": "library",
      "name": "handlebars",
      "version": "3.0.3-tuxcare.1",
      "purl": "pkg:npm/handlebars@3.0.3-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d0d6cba9-06f9-5cdc-8e4f-1b5881092b6d",
      "id": "CVE-2015-8861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8861 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ad4177f-ff30-51c8-810a-1d5a2d4be671",
      "id": "CVE-2019-19919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-19919 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b092ef8e-a827-540c-a24f-b36c27aa28fd",
      "id": "CVE-2019-20920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20920 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ead9c30a-453c-583e-9315-f0833f186bb0",
      "id": "CVE-2021-23369",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23369 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a758ba17-86d2-5d66-a4bf-ae36ee3016f1",
      "id": "CVE-2021-23383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23383 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05a2dcd7-33c0-522b-90f7-3cf432f1d83e",
      "id": "CVE-2024-45801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45801 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5abcd432-03df-506d-b010-5c2e63e262b5",
      "id": "CVE-2024-47875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47875 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30594868-51ce-5c5e-b510-4f577ab5cc11",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e784b9f7-bc02-5f36-b461-471712607721",
      "id": "CVE-2025-32996",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32996 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71334af9-b760-59fd-b0ae-9957d02331d6",
      "id": "CVE-2025-32997",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32997 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d6a67de-e9e0-5d96-bd4c-662f48d9ccc7",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0540 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed9ae63-8d72-5d44-a609-9087401c2c0e",
      "id": "CVE-2026-13676",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-13676 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2deb2549-de30-54f6-9eaf-21ce3779dabf",
      "id": "CVE-2026-16221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-16221 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f868b70-4a92-59ab-a6d5-073a5062eeb7",
      "id": "CVE-2026-33937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33937 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c97101ce-17d6-5517-a24c-4185a8ba210b",
      "id": "CVE-2026-33938",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33938 does not affect version 3.0.3-tuxcare.1 of handlebars. Version 3.0.3 is not vulnerable. Summary: The target repository (Handlebars 3.0.3) is not vulnerable to CVE-2026-33938. The vulnerability affects versions 4.0.0 through 4.7.8, and the target is running an older version (3.0.3) that predates the vulnerable @partial-block feature. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65112ab7-6e42-51cf-bc7b-729108e483c4",
      "id": "CVE-2026-33939",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33939 does not affect version 3.0.3-tuxcare.1 of handlebars. Version 3.0.3 is not vulnerable. Summary: Target repository runs Handlebars version 3.0.3, which predates the vulnerable versions (4.0.0 through 4.7.8). The decorator feature that contains the vulnerability does not exist in this version. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282d2e43-8642-568c-b784-c76590ce1b6d",
      "id": "CVE-2026-33940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33940 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473406a6-3399-5946-9d1f-eef18c414533",
      "id": "CVE-2026-33941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33941 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:633feb29-5a6e-5832-bcd5-a9a7c9e7bd62",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a12d862-cb42-5f85-a858-8ec7d5da8fce",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44bcc547-324a-5237-8275-9d9ec7dc6e5e",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d58052f-25c2-5080-8024-030f40342497",
      "id": "CVE-2026-55602",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55602 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e1b5a97-bc48-53ab-a332-e541942a3bd9",
      "id": "CVE-2026-6321",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6321 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:843f5d9e-2636-535a-9d44-b37096195605",
      "id": "CVE-2026-6322",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6322 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38edcc0e-d207-5c67-804e-08bfcbd96b01",
      "id": "GHSA-2cf5-4w76-r9qv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-2cf5-4w76-r9qv is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed6303e-f14d-5955-894e-ba67d9b39a02",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcdef4ed-8746-56d2-bb45-9d910f050110",
      "id": "GHSA-442j-39wm-28r2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 3.0.3-tuxcare.1 of handlebars. Version 3.0.3 is not vulnerable. Summary: The target repository does not contain the TOCTOU (Time-of-Check Time-of-Use) vulnerability described in GHSA-442j-39wm-28r2. The target's lookup function does not use the vulnerable pattern where lookupProperty() is called but its result is discarded. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4af75486-6769-505b-bc24-2d81facf9680",
      "id": "GHSA-6r5x-hmgg-7h53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r5x-hmgg-7h53 is a false positive for handlebars 3.0.3-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5356ae29-d2bb-50cd-b08c-2bc8e6537708",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ac5862e-cb7d-571d-b067-ae8166d050b9",
      "id": "GHSA-7rx3-28cr-v5wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a9942db-3260-55d2-8a4b-9ab21471bf4c",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb26b951-c489-55a9-aa10-b4f560136b10",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc628f6d-f523-5463-b889-f03734a1807a",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01ac0e18-18a5-581a-b2ae-e87fba7f588c",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a119a73-6b00-5534-958c-916799438665",
      "id": "GHSA-fmr4-7g9q-7hc7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fmr4-7g9q-7hc7 is a false positive for handlebars 3.0.3-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b5b93ec-d013-58e5-a707-b8acf40759f3",
      "id": "GHSA-g9r4-xpmj-mj65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-g9r4-xpmj-mj65 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c1ae45-352c-54f9-84bc-38d1ca98665b",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6d1c749-0acb-55a7-8a06-676a3e8ed5c4",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b157869a-2cd9-5b2c-bb33-31cdba5586d6",
      "id": "GHSA-q2c6-c6pm-g3gh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q2c6-c6pm-g3gh is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5901b9a5-01e5-588a-a30b-f59551662d0d",
      "id": "GHSA-q42p-pg8m-cqh6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q42p-pg8m-cqh6 is fixed in version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90c19671-f085-5b5b-ab2e-9718431b8508",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e09b74-9c72-52bb-892a-e4846310e367",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 affects version 3.0.3-tuxcare.1 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/handlebars@3.0.3-tuxcare.1"
    }
  ]
}