{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:78ddc3ff-37da-505e-8ed9-cf4a0d54499b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/lodash@3.10.1-tuxcare.2",
      "type": "library",
      "name": "lodash",
      "version": "3.10.1-tuxcare.2",
      "purl": "pkg:npm/lodash@3.10.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6510b7c8-c439-5ded-9e8d-cb03119e3d0a",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.10.1-tuxcare.2 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb065edd-d109-5fc6-bf96-c6545ad0a79a",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.10.1-tuxcare.2 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5946011b-ee3e-5c07-906e-9e2eed5fae63",
      "id": "CVE-2019-1010266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-1010266 does not affect version 3.10.1-tuxcare.2 of lodash. not_affected \u2014 lodash v3.10.1-tuxcare.2 is NOT affected by CVE-2019-1010266. The target version uses a structurally different regex pattern for word matching and already implements character-iteration-based trimming, neither of which exhibit the catastrophic backtracking behavior that makes v4.x vulnerable. Empirical testing confirms v3.10.1 processes attack strings in 1ms vs 2186ms for the vulnerable v4.x pa..."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dae8244-2e80-518d-81e7-2694fdbe6cc0",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.10.1-tuxcare.2 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acf749f4-3a02-554b-89da-97489d80f2fd",
      "id": "CVE-2020-28500",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-28500 does not affect version 3.10.1-tuxcare.2 of lodash. not_affected \u2014 CVE-2020-28500 does NOT affect lodash version 3.10.1. The vulnerability was introduced in lodash v4.x and never existed in v3.x. Version 3.10.1 uses manual character iteration with linear time complexity, eliminating the ReDoS vulnerability that affects v4.0.0-4.17.20."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38dd0c96-7dd0-57e4-b040-5405f9be6871",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.10.1-tuxcare.2 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a3530e8-bf82-53b9-9120-975cffa183db",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.10.1-tuxcare.2 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b016f1-12b2-5e4e-8487-482c79758938",
      "id": "CVE-2021-41720",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41720 is a false positive for lodash 3.10.1-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3e6cee-5a5f-566a-8cd3-0b90b7b4a5ce",
      "id": "CVE-2025-13465",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-13465 does not affect version 3.10.1-tuxcare.2 of lodash. not_affected \u2014 lodash 3.10.1 is not affected by CVE-2025-13465. The vulnerability requires the baseUnset function with path-based deletion mechanism introduced in lodash 4.0.0. Version 3.10.1 lacks _.unset entirely, and its _.omit implementation uses a copy-based architecture without path traversal or delete operations."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a85ec6-040f-5cb4-8ef7-cf97e5653c47",
      "id": "CVE-2026-2950",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2950 does not affect version 3.10.1-tuxcare.2 of lodash. not_affected \u2014 Lodash 3.10.1 is not affected by CVE-2026-2950. The vulnerability requires the baseUnset function and _.unset method which do not exist in version 3.10.1. The _.omit implementation in 3.10.1 creates new objects via pickByArray rather than deleting properties, and no path-based deletion mechanism exists."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1791a7a-fd18-53e7-b9ae-1edea129b225",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 3.10.1-tuxcare.2 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash@3.10.1-tuxcare.2"
    }
  ]
}