{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4d2760f6-3d36-501d-b45e-580135a351c8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/handlebars@3.0.3-tuxcare.2",
      "type": "library",
      "name": "handlebars",
      "version": "3.0.3-tuxcare.2",
      "purl": "pkg:npm/handlebars@3.0.3-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c6e8f4ce-223a-542f-b8f0-159537d1a1c3",
      "id": "CVE-2015-8861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8861 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbc934cc-e944-58f2-ab2e-eaa980317ed2",
      "id": "CVE-2019-19919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-19919 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55f3507c-9087-5723-b677-f6d56b1433ee",
      "id": "CVE-2019-20920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20920 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e27b8e-3b23-544f-a4eb-2d6899a24f73",
      "id": "CVE-2021-23369",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23369 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a781e5f8-d6e1-53cb-bfe9-66d936d81659",
      "id": "CVE-2021-23383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23383 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35ef434f-ab94-5733-9906-c2b8a8ff8ced",
      "id": "CVE-2024-45801",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45801 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ea06376-ada8-5273-b8ca-5e957b320eee",
      "id": "CVE-2024-47875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47875 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1feef7b4-dd74-5dac-9f92-5fffaa87081f",
      "id": "CVE-2025-26791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26791 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48c3bb9-234d-5753-bba1-0caded4da386",
      "id": "CVE-2025-32996",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32996 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e6e00a0-e388-5f75-9f81-544d15815890",
      "id": "CVE-2025-32997",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32997 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fee14dd-77b9-56c2-9ffd-7f40c83228ef",
      "id": "CVE-2026-0540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0540 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:090d82a1-f574-5988-a3a2-924b3b9d01a9",
      "id": "CVE-2026-13676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-13676 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbfd6c1a-7384-5df1-8039-26743655d663",
      "id": "CVE-2026-16221",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-16221 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0fb0715-5999-51d7-94ca-434db1592f1a",
      "id": "CVE-2026-33937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33937 affects version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7384850e-4e9c-54fd-815e-91e6c99b18c9",
      "id": "CVE-2026-33938",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33938 does not affect version 3.0.3-tuxcare.2 of handlebars. Version 3.0.3 is not vulnerable. Summary: The target repository (Handlebars 3.0.3) is not vulnerable to CVE-2026-33938. The vulnerability affects versions 4.0.0 through 4.7.8, and the target is running an older version (3.0.3) that predates the vulnerable @partial-block feature. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd8a910-45cc-560a-905e-d0246cc70895",
      "id": "CVE-2026-33939",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33939 does not affect version 3.0.3-tuxcare.2 of handlebars. Version 3.0.3 is not vulnerable. Summary: Target repository runs Handlebars version 3.0.3, which predates the vulnerable versions (4.0.0 through 4.7.8). The decorator feature that contains the vulnerability does not exist in this version. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:404d23ed-f92b-572b-8f10-f5d4fcd48584",
      "id": "CVE-2026-33940",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33940 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db94b687-0826-58bb-85b6-e272d42d9dfc",
      "id": "CVE-2026-33941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33941 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f2274d-75e2-5b9c-9b13-3741d815c168",
      "id": "CVE-2026-41238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41238 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06c15b43-3bbe-5f0c-9ee0-44a1eb966fb6",
      "id": "CVE-2026-41239",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41239 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a8363c-c1c4-5136-a1b9-491b724aeaab",
      "id": "CVE-2026-41240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41240 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba507f38-2a1e-5a32-9cc3-f8f736a76c7f",
      "id": "CVE-2026-55602",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55602 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acdb30de-ab5c-5892-b278-1936cbff0c74",
      "id": "CVE-2026-6321",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6321 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3426ef66-a488-5359-b6c5-2eacaf9c6d5a",
      "id": "CVE-2026-6322",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6322 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3742ad90-bb9e-5485-8ea5-b28a06467459",
      "id": "GHSA-2cf5-4w76-r9qv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-2cf5-4w76-r9qv is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f2109c-44d2-55ef-ac81-bbbd92e30253",
      "id": "GHSA-39q2-94rc-95cp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-39q2-94rc-95cp is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173850aa-ebf5-5c41-8a85-a53dfae0e3f3",
      "id": "GHSA-442j-39wm-28r2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 3.0.3-tuxcare.2 of handlebars. Version 3.0.3 is not vulnerable. Summary: The target repository does not contain the TOCTOU (Time-of-Check Time-of-Use) vulnerability described in GHSA-442j-39wm-28r2. The target's lookup function does not use the vulnerable pattern where lookupProperty() is called but its result is discarded. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c0727f-1596-5d4c-9395-34537566dc1b",
      "id": "GHSA-6r5x-hmgg-7h53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r5x-hmgg-7h53 is a false positive for handlebars 3.0.3-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64486360-41c7-56e7-8d2f-d7b951616336",
      "id": "GHSA-76mc-f452-cxcm",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-76mc-f452-cxcm is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:201261ea-8120-50b1-92fb-16bcff7dd013",
      "id": "GHSA-7rx3-28cr-v5wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb9ccc68-01d8-570e-b6b6-188b197a56e8",
      "id": "GHSA-c2j3-45gr-mqc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2j3-45gr-mqc4 affects version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5dcfd1a-68bc-5a0c-8a74-a2ecb5a2fa8c",
      "id": "GHSA-cj63-jhhr-wcxv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cj63-jhhr-wcxv is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a676063-3352-5018-9438-d7edd850b21c",
      "id": "GHSA-cjmm-f4jc-qw8r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cjmm-f4jc-qw8r is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffe7e1dd-b138-5753-a056-d21ca390c3b1",
      "id": "GHSA-cmwh-pvxp-8882",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cmwh-pvxp-8882 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25fa625f-9921-5283-a844-5b60cfd5846d",
      "id": "GHSA-fmr4-7g9q-7hc7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fmr4-7g9q-7hc7 is a false positive for handlebars 3.0.3-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef3586dd-954e-54b3-a9f6-750abd801247",
      "id": "GHSA-g9r4-xpmj-mj65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-g9r4-xpmj-mj65 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da975358-5235-5ade-8064-0420d65640e4",
      "id": "GHSA-gvmj-g25r-r7wr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gvmj-g25r-r7wr is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f46a053-d661-54bd-901e-9282cbad9097",
      "id": "GHSA-h8r8-wccr-v5f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h8r8-wccr-v5f2 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195e3790-5637-5b46-92f8-07a81b861537",
      "id": "GHSA-q2c6-c6pm-g3gh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q2c6-c6pm-g3gh is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50b2e6ab-b9f7-5229-90c7-7be51d6679dd",
      "id": "GHSA-q42p-pg8m-cqh6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q42p-pg8m-cqh6 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b7c46cd-1c01-5090-8449-0518a5d3a5c5",
      "id": "GHSA-vxr8-fq34-vvx9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vxr8-fq34-vvx9 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa243ee6-5945-5301-a105-6f33ec9a975a",
      "id": "GHSA-x4vx-rjvf-j5p4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x4vx-rjvf-j5p4 is fixed in version 3.0.3-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/handlebars@3.0.3-tuxcare.2"
    }
  ]
}