{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ce2acc67-73c6-5bd4-8b06-4f0ff0cf3409",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2",
      "type": "library",
      "name": "nodemailer",
      "version": "2.7.2-tuxcare.2",
      "purl": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d1b9be5e-75a3-5a5e-92c9-98d35f81a08b",
      "id": "CVE-2020-7769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7769 is fixed in version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed4fc691-2ba3-5c49-bb65-9f76abeb75f5",
      "id": "CVE-2021-23400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23400 is fixed in version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715ab893-1ecf-5562-a679-1f9b02585527",
      "id": "CVE-2025-13033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13033 is fixed in version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a2f033-5c38-5045-b92a-63c5abc409cd",
      "id": "CVE-2025-14874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14874 is fixed in version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59190221-007c-567c-b001-9ebd4c49aee7",
      "id": "GHSA-268h-hp4c-crq3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-268h-hp4c-crq3 affects version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da63e226-eaa8-5b3f-8b36-abcae3a41acf",
      "id": "GHSA-46j5-6fg5-4gv3",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-46j5-6fg5-4gv3 is a false positive for nodemailer 2.7.2-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4883aaf0-87a9-5b48-89ab-003a82cc3af5",
      "id": "GHSA-9h6g-pr28-7cqp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-9h6g-pr28-7cqp is fixed in version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88a6428-d5e2-54bd-a511-3632c41d5c46",
      "id": "GHSA-c7w3-x93f-qmm8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c7w3-x93f-qmm8 does not affect version 2.7.2-tuxcare.2 of nodemailer. not_affected \u2014 The target nodemailer v2.7.2 repository uses a modular architecture where SMTP transport functionality is externalized to the 'nodemailer-smtp-transport' npm package. While the target's lib/buildmail/index.js accepts and stores custom envelope.size values without validation (lines 754-759), the SMTP command construction code that would concatenate this value into the 'MAIL FROM' command does no..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f06787f-12ca-5b71-936c-7baf3cae0a7c",
      "id": "GHSA-jj37-3377-m6vv",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-jj37-3377-m6vv is a false positive for nodemailer 2.7.2-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87b632fc-e19e-5058-a25d-1a252aa5e85b",
      "id": "GHSA-mm7p-fcc7-pg87",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mm7p-fcc7-pg87 does not affect version 2.7.2-tuxcare.2 of nodemailer. already_fixed \u2014 CVE-2025-13033 (GHSA-mm7p-fcc7-pg87) has already been fixed in target version 2.7.2-tuxcare.2. The identical security fix from upstream nodemailer v7.0.7 was backported by TuxCare in commit 47f6ead (December 25, 2025). The defense prevents email misrouting by tracking quote boundaries during parsing and preventing email address extraction from quoted text tokens."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d8d194d-b772-58c3-9677-93ffd02c8eba",
      "id": "GHSA-p6gq-j5cr-w38f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-p6gq-j5cr-w38f affects version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad7f8c5-85f4-5632-aea2-ab4894519438",
      "id": "GHSA-r7g4-qg5f-qqm2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-r7g4-qg5f-qqm2 does not affect version 2.7.2-tuxcare.2 of nodemailer. not_affected \u2014 Version 2.7.2 is not affected by GHSA-r7g4-qg5f-qqm2. The vulnerable code paths (lib/fetch/index.js with rejectUnauthorized:false and lib/xoauth2/index.js for OAuth2 token retrieval) were introduced in version 3.0.0 and do not exist in version 2.7.2. This version does not implement OAuth2 token retrieval functionality - it only supports XOAUTH2 SMTP authentication with pre-provided tokens."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60ad5247-f4c4-571d-93ee-addab8709f42",
      "id": "GHSA-rcmh-qjqh-p98v",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-rcmh-qjqh-p98v is fixed in version 2.7.2-tuxcare.2 of nodemailer."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79c98807-72ba-5672-93c4-d71c0289401c",
      "id": "GHSA-vvjj-xcjg-gr5g",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-vvjj-xcjg-gr5g does not affect version 2.7.2-tuxcare.2 of nodemailer. not_affected \u2014 The target repository (nodemailer 2.7.2) does not contain the vulnerable code. In version 2.7.2, SMTP connection functionality exists in separate npm packages (nodemailer-smtp-transport, nodemailer-smtp-pool) that are not vendored or bundled in this repository. The vulnerable code path (lib/smtp-connection/index.js processing the name option and sending EHLO/HELO commands) was added in version ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee3073e-571a-5fd4-9937-c1ba66e2a330",
      "id": "GHSA-wqvq-jvpq-h66f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-wqvq-jvpq-h66f does not affect version 2.7.2-tuxcare.2 of nodemailer. not_affected \u2014 Version 2.7.2 does not contain the jsonTransport feature or any pre-MIME content resolution path that would bypass access flag enforcement. The vulnerable code path described in GHSA-wqvq-jvpq-h66f does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nodemailer@2.7.2-tuxcare.2"
    }
  ]
}