{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:239fb503-1ac7-5ab3-83b4-6cd8ec0e49f0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nuxi@3.2.0-tuxcare.1",
      "type": "library",
      "name": "nuxi",
      "version": "3.2.0-tuxcare.1",
      "purl": "pkg:npm/nuxi@3.2.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fb3c8ad7-0183-55f7-bc6c-cd3a4ef3bf5f",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6df53bb3-ca63-553e-a3fb-f2f8d7e854e6",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c7f290e-e391-53e7-a19c-61ab6be61945",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386f62a2-f3fa-5d87-8054-ac9a08753ee0",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60cb8e1f-5159-5345-b0b8-2fe23ab7b0f3",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f9d348-b762-51bb-973c-50570e52b500",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31cb281a-1714-57f1-9979-98d65d6dcd4f",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17363720-dd64-523c-b332-d2f3f54a3e68",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8276dae2-38f7-5dc4-8333-ca35e02eda70",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61395537-ea14-5ac5-b4fe-0e515ec432df",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bb134d0-c276-5731-9e40-332cd60cca19",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68c38311-7013-5037-b143-6c7bfefdc733",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-8203 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68607e6c-07db-5810-a6ac-af50354b45ba",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26591205-9394-54fb-be26-a9c83d6db4b2",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dbf1896-8216-54e4-ab48-f58aa42ac5bd",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e2f828-63d8-5499-b0c1-8c36f921f5bb",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe0e3f49-c939-5d40-bc2c-5018a0412e3a",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03bd547f-cb1a-5710-a506-de942296a0c6",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f78dc8b6-c199-52cb-b5ee-953f29b3da2f",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:313e97eb-9b3d-5487-9194-f93890acd5ac",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16afdfaf-c5fe-5fdb-85c0-671a78d5b50d",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec229ba6-bda2-511b-9e30-bedee5fb642e",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33151 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3683d85-155b-5ea2-b785-d6043de25897",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:139e9fe2-e560-5e6f-a8ff-48bd3f73a40a",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for nuxi 3.2.0-tuxcare.1. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83796fdb-a34e-5e0c-8cbf-ed0ab6d0a055",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf5f7989-9d20-5c4d-9a83-0ef56268ad54",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84014d78-0a2b-52fe-b855-86008b8d341c",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.1 of nuxi. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:673d92f2-7f50-5138-8978-df981b474033",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac8a9a48-f742-52a9-b8d8-601fdc203f15",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.1 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4495de55-3c00-56d0-863d-018d16574675",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.1 of nuxi. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b47165b1-044a-5a05-b257-859334170ada",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.1 of nuxi. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dfdd067-009b-57bc-9e91-65838f2ea679",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.1 of nuxi. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nuxi@3.2.0-tuxcare.1"
    }
  ]
}