{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e405fa7b-cf4a-527f-8204-67f5ab2c6bf7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/nuxi@3.2.0-tuxcare.2",
      "type": "library",
      "name": "nuxi",
      "version": "3.2.0-tuxcare.2",
      "purl": "pkg:npm/nuxi@3.2.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dcdd6ffc-64d3-5860-97b7-2a386935d7ca",
      "id": "CVE-2016-10735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10735 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d859fcd-26bf-5639-a3ee-734193f22d5d",
      "id": "CVE-2018-14040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14040 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e3433a-8021-532d-936b-7c75763b2951",
      "id": "CVE-2018-14042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-14042 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca6ae59-5dee-5dec-8057-15b73be314d4",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64b52ca3-2706-5599-87e8-23e287dc6221",
      "id": "CVE-2018-20676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20676 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d7d9af2-786e-5126-86d1-01609664cde7",
      "id": "CVE-2018-20677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20677 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:135043bd-36e3-5c06-b34a-17ea80a88cd1",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3be3e69-b96d-55b2-94ad-93f912976f70",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cd3eae6-d4c5-589f-a4fe-931d634cb02c",
      "id": "CVE-2019-14862",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-14862 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e941623-2d5a-5c89-bccc-d7395cde83b6",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81273eca-b976-5146-850b-76d399264bb0",
      "id": "CVE-2020-36049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36049 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55228a0e-8f67-5f8c-82ab-b728bbdd5380",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76cf9370-b25a-5fd2-a097-953b5f153049",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa77ee0a-dbdb-596c-bc7f-ade81960cf05",
      "id": "CVE-2022-2421",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2421 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a6f217-78f5-53d0-8263-1f1f39ed2766",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25852 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32f3afb1-43db-5100-94b5-5593e7072cff",
      "id": "CVE-2023-32695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32695 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bdec1f5-65bd-52ac-93e7-c23d7816f6a0",
      "id": "CVE-2024-34343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a1c49c-4b0d-5975-9c8a-0ff3e8ebc7af",
      "id": "CVE-2024-6484",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6484 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f3bfe20-6bc7-5458-a6ab-eed7fb3068a3",
      "id": "CVE-2024-6485",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6485 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e90de09-b8d9-5b6a-a8a4-2b2d4a495fa3",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce662085-839c-57a7-879e-64258bf60904",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:854a6730-1e9a-5ed5-b56a-18d74211b9f3",
      "id": "CVE-2026-33151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33151 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4ba3d9-1809-5fd1-afac-832e0228c7bd",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17e8a243-690e-5a4b-9185-64170156f375",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for nuxi 3.2.0-tuxcare.2. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5312e5f5-5f5c-52d4-b6e0-46042bff7257",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:225f93b8-24d0-5246-9de9-37c39c34bff6",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9e9f3a0-cf48-52c0-be94-19a0112a76ce",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.2 of nuxi. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d295521d-d855-5ca5-b0a7-f45a2e5e2111",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4800 is fixed in version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca8d8e3-9cc2-50dc-9ecf-577fccc5ec01",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.2 of nuxi."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60fe748b-6b58-5197-b84e-bc7632c7f3e4",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.2 of nuxi. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d553a3b1-c539-500a-a1ec-c498d92c9d06",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.2 of nuxi. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a36c2b-1fca-5e29-9078-27cd78ba5480",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.2 of nuxi. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment."
      },
      "affects": [
        {
          "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nuxi@3.2.0-tuxcare.2"
    }
  ]
}