{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5da96e8a-1054-5fc3-a55c-209e907dc22b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1",
      "type": "library",
      "name": "jsonwebtoken",
      "version": "0.3.0-tuxcare.1",
      "purl": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f57f0406-1e21-5b7e-9c10-99831638c8f2",
      "id": "CVE-2015-8315",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8315 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915d2c86-6e8b-596b-8de5-806ef895570d",
      "id": "CVE-2015-9235",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-9235 affects version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19abd81-8d58-5f6e-b7ce-6ebe4291f9af",
      "id": "CVE-2016-10539",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10539 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:553a8728-7823-58b5-916c-04f9c536da95",
      "id": "CVE-2016-10540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10540 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7a9263e-693c-5339-9c46-a5866671cdb3",
      "id": "CVE-2017-16119",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16119 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc9f2135-123b-5c68-b9cb-dad258b66e96",
      "id": "CVE-2017-20162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20162 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de82744e-4668-55ee-996a-ef267002e6f5",
      "id": "CVE-2021-29060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-29060 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a22d67e6-f00e-5bfd-a42f-31e0b63335cc",
      "id": "CVE-2022-0144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-0144 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73ed5f28-3d2f-5c3a-a3d8-3b2755b57503",
      "id": "CVE-2022-23529",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-23529 is a false positive for jsonwebtoken 0.3.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5449e5b-916d-539a-8922-b746b8210727",
      "id": "CVE-2022-23539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23539 affects version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef6a68c3-eb8e-580d-8175-959f2b6a793f",
      "id": "CVE-2022-23540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23540 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e861b044-9b89-59e9-aeea-d71414777a3b",
      "id": "CVE-2022-23541",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23541 affects version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30855e6f-1f48-5300-9289-9f5a5f7b3d0d",
      "id": "CVE-2022-25875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25875 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e046a360-802c-58ea-abf8-11aaeaf3ff44",
      "id": "CVE-2022-3517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-3517 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb1fdfef-f551-5547-8ad3-f57d457e0dc2",
      "id": "CVE-2024-45047",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45047 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30bbc7f-2cce-5e7c-bc73-2dfe0d3b7b61",
      "id": "CVE-2026-25537",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-25537 is a false positive for jsonwebtoken 0.3.0-tuxcare.1. false_positive \u2014 This advisory concerns a completely different project. The CVE-2026-25537 affects the Rust jsonwebtoken crate (github.com/Keats/jsonwebtoken), while the target repository is the JavaScript/Node.js jsonwebtoken package (github.com/auth0/node-jsonwebtoken). Despite sharing the same package name, these are distinct implementations in different languages by different authors with no code relationship."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6019e7dd-5dae-5642-a9f5-2842cdf92467",
      "id": "CVE-2026-27121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27121 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a0da58c-39b4-525f-93d6-30301e66250c",
      "id": "CVE-2026-27122",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27122 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf75307c-c0ca-5ed9-a087-2d001231306f",
      "id": "CVE-2026-27125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27125 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdf01a02-d158-5b01-8c47-5fc6f4a14806",
      "id": "CVE-2026-27901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27901 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2154bd-943b-5be7-a15d-6d7c3f4e7bce",
      "id": "GHSA-64g7-mvw6-v9qj",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-64g7-mvw6-v9qj is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23671c48-25be-5119-8362-e35d53315683",
      "id": "GHSA-xc7v-wxcw-j472",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xc7v-wxcw-j472 is fixed in version 0.3.0-tuxcare.1 of jsonwebtoken."
      },
      "affects": [
        {
          "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/jsonwebtoken@0.3.0-tuxcare.1"
    }
  ]
}