{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7b11cae-ab5f-5bea-943d-5033712df972",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "nodemailer",
      "purl": "pkg:npm/nodemailer@6.10.1-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10",
      "version": "6.10.1-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-13033",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2ffa5d8b-9a89-55f3-b11c-655885b4f4e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13033 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2025-14874",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:fbd81554-0439-5cc1-b9d6-6b2d2ac75abe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14874 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-82659",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:231880a7-b6af-5822-80ba-5d926c15406c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82659 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-82660",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ca9d08fd-82b2-5a8f-b0cc-b1e3bfa4581c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82660 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-82661",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:3493d140-25a3-5425-81d7-fb4a626c5823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82661 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-82662",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:488e99d6-fb19-5d7d-815d-788d0132878d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82662 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-82853",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e6c9e409-f409-5cf1-a73a-0050045feb5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82853 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-82854",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2e3b8e98-d888-5507-9600-b7c8e9de465c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82854 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "CVE-2026-92595",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bfd4ebc1-c44d-5d6c-aa1a-5a05113b3a4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-92595 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-268h-hp4c-crq3",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bb1b4ff8-256a-5a52-80b6-16b9e57521d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-268h-hp4c-crq3 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-2x7j-588g-ccc2",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:17c6f3c5-0f87-5a2d-8b77-a8ae97d7a005",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-2x7j-588g-ccc2 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-46j5-6fg5-4gv3",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:def43971-6561-5651-a3b4-f8c22710e609",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-46j5-6fg5-4gv3 is a false positive for nodemailer 6.10.1-tuxcare.10."
      }
    },
    {
      "id": "GHSA-8m3c-c648-2xjj",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:34a1c655-0d42-50f2-aadc-ac34e37fa0d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8m3c-c648-2xjj is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-c7w3-x93f-qmm8",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:aed1e6a0-c3f3-5159-bd98-65e2993eea61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c7w3-x93f-qmm8 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-cc9r-2j5m-2m83",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:41393a12-bb4b-5176-8f79-10f89133fe21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cc9r-2j5m-2m83 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-h3hj-cmcx-xc66",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:cbf25739-54a8-5bb9-8503-ce72d2eb85a8",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-h3hj-cmcx-xc66 is a false positive for nodemailer 6.10.1-tuxcare.10."
      }
    },
    {
      "id": "GHSA-jj37-3377-m6vv",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7aa972a7-992d-5381-9ba4-b99de68cc0d0",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-jj37-3377-m6vv is a false positive for nodemailer 6.10.1-tuxcare.10."
      }
    },
    {
      "id": "GHSA-mm7p-fcc7-pg87",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ca1ea0a3-9ffd-5979-a8d0-c19ac5fefd23",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mm7p-fcc7-pg87 does not affect version 6.10.1-tuxcare.10 of nodemailer. already_fixed \u2014 The target repository (nodemailer 6.10.1-tuxcare.3) already contains the complete security fix for CVE-2025-13033/GHSA-mm7p-fcc7-pg87. The fix was backported by TuxCare on December 9, 2025 via commit 189d7aa. The vulnerability involved incorrect parsing of quoted local-parts containing @ symbols, which could cause email misrouting to attacker-controlled domains. The fix adds quote state trackin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-p6gq-j5cr-w38f",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:bddb9d6e-3af1-595e-a670-7ed7c230369b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-p6gq-j5cr-w38f is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-r7g4-qg5f-qqm2",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:1b11656e-8a31-5990-9e65-68a2bd5f1a44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-r7g4-qg5f-qqm2 is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-vvjj-xcjg-gr5g",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ce0849bf-fece-58fb-bce1-754d6a40bd7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vvjj-xcjg-gr5g is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-wmmp-3585-3rmp",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8ae32468-7872-5995-9ff5-32212913e685",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wmmp-3585-3rmp is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    },
    {
      "id": "GHSA-wqvq-jvpq-h66f",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:608e774d-ddf8-587f-8503-80d4150efd5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wqvq-jvpq-h66f is fixed in version 6.10.1-tuxcare.10 of nodemailer."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nodemailer@6.10.1-tuxcare.10"
    }
  ]
}