{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1e60bac6-6e4a-5cb2-ba9e-c490dc458b7d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/moment@2.0.0-tuxcare.1",
      "type": "library",
      "name": "moment",
      "version": "2.0.0-tuxcare.1",
      "purl": "pkg:npm/moment@2.0.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8477bdac-6ca7-5875-a12a-cf0c085d82f9",
      "id": "CVE-2016-4055",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-4055 does not affect version 2.0.0-tuxcare.1 of moment. not_affected \u2014 Version 2.0.0 of moment.js is not affected by CVE-2016-4055. The vulnerable aspNetRegex for duration parsing that causes ReDoS was introduced in version 2.11.0 (November 2015) and fixed in version 2.11.2 (February 2016). Version 2.0.0 predates the introduction of this feature entirely - it does not parse duration strings with regex and simply returns a zero duration when given arbitrary string ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fa9c9da-30e9-5dbc-8f9b-569fd26838f8",
      "id": "CVE-2017-18214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-18214 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97bdf738-8eca-563f-b450-3d89de171be1",
      "id": "CVE-2017-20162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20162 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfeda227-752a-5ffd-a98c-8584bda80ad5",
      "id": "CVE-2019-10747",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10747 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2091b2b7-5bcf-55ba-bf34-8034c6fef028",
      "id": "CVE-2021-23440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23440 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab3c467a-da5a-5d79-82c6-f2e92e76a834",
      "id": "CVE-2021-23807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23807 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e930d29-091d-5a68-8203-a38d2fb0da46",
      "id": "CVE-2021-33623",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33623 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c496d83-1dc5-57af-8bb2-6b2f327bf638",
      "id": "CVE-2022-24785",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24785 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7163bef5-6734-5ca4-bb55-1fa18e0b2414",
      "id": "CVE-2022-37599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-37599 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dc5fb53-d534-551a-9dcd-2ef7efc55de6",
      "id": "CVE-2022-37601",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-37601 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:931749ac-a5f5-5774-a490-7ebbbaaeaf77",
      "id": "CVE-2022-37603",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-37603 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:630815cc-2a04-5b7c-aff1-7b5663d5abd3",
      "id": "CVE-2023-42282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42282 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e410147c-d55d-5b08-b166-7886d7040101",
      "id": "CVE-2025-7783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-7783 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51da257f-b775-5dbf-85af-6272d0f1df54",
      "id": "CVE-2026-3449",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3449 is fixed in version 2.0.0-tuxcare.1 of moment."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad188e5-df20-5e4b-b75e-20313e1d0b0f",
      "id": "GHSA-hxf5-mg84-pj4m",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-hxf5-mg84-pj4m is a false positive for moment 2.0.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/moment@2.0.0-tuxcare.1"
    }
  ]
}