{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c4e48980-4c85-5508-8d99-bec3d499a517",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "2.2.1-tuxcare.1",
      "purl": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f6abaf87-6cfe-51d2-b434-d4b2114f2c6b",
      "id": "CVE-2018-3738",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3738 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebfc55f7-36d9-5b78-941e-becb6e4551e2",
      "id": "CVE-2020-26311",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-26311 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b9dc18d-2cd6-545e-99b0-0dc4149dc533",
      "id": "CVE-2021-32804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32804 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf34bb7d-0750-5aeb-8976-38f5b739a9d4",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41242 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 2.2.1 is not affected by CVE-2026-41242. The vulnerability exists in the modern modular architecture (versions 6.x-8.x) in src/type.js, which does not exist in version 2.2.1. Version 2.2.1 uses a completely different architecture with runtime class creation and enforced name validation via Lang.NAME regex, preventing the code injection attack vector described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8541b416-0a2c-5398-a6ee-3727d38d29d5",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44288 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 2.2.1 does not contain the vulnerable minimal UTF-8 decoder described in CVE-2026-44288. This version uses ByteBuffer.js as an external dependency for all UTF-8 string decoding operations, predating the introduction of protobufjs's internal minimal UTF-8 decoder in later versions (6.x/7.x)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b5b1369-d624-50c8-a3ff-5654dfe7151a",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6414e76-324e-51dc-8229-184cc4e7df70",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44290 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c77f0a-3b1f-53cf-b343-a3b4ec82131e",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44291 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7334dfee-d2c7-5c9a-9cf5-68d20d89b12f",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44292 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 2.2.1 uses validated property assignment through the `$set()` method which checks all keys against defined fields. When `__proto__` is provided in the properties object (and is not a defined field), the `set()` method throws an error before any assignment occurs, preventing prototype modification. This validation defense does not exist in the vulnerable upstream versions 6.x-7.x, which ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:106b0af3-328c-5aa5-bf94-bd47acc204d3",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44293 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 The target protobufjs version 2.2.1 uses a fundamentally different architecture (runtime Builder pattern with JSON.stringify/JSON.parse) compared to the vulnerable version 7.x (static code generation with util.codegen). The vulnerability CVE-2026-44293 requires dynamic code generation with unsafe string interpolation of bytes field defaults, which does not exist in version 2.2.1. The target pro..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa62286d-5daf-5392-8986-5ccdfc610f6c",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44294 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f3baf6c-bd73-5325-9a84-58cf4136f2b1",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f314a619-373c-58dd-883d-48f06a0f26c0",
      "id": "CVE-2026-46625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46625 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42200073-fb16-5657-9e1a-f0cdb185e397",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:445e1c9d-e8c7-51aa-beb4-a077418983d0",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54269 is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66f8b306-9c98-5c29-84a6-c3c81c021986",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 protobufjs version 2.2.1 is not affected by CVE-2026-54270. The vulnerability concerns versions 8.2.0 through pre-8.6.2 that preserve unknown fields in message.$unknowns by default. Version 2.2.1 predates this feature entirely and always discards unknown fields during decode, making the memory exhaustion attack path impossible."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4717a257-c76b-5391-9b4a-bbe7f33e5e70",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 CVE-2026-59876 targets the optional Text Format extension (protobufjs/ext/textformat) for handling map fields with __proto__ keys. Version 2.2.1 does not have the Text Format extension or map support, as it predates proto3 (which introduced maps). The vulnerability pattern does not apply to this version's architecture."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d622bedf-7064-5cbc-8f74-ad061be6a4fd",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 2.2.1-tuxcare.1 of protobufjs. not_affected \u2014 The target protobufjs version 2.2.1 is not affected by CVE-2026-59877. The vulnerability requires a specific `while (token !== \"=\")` loop pattern in option name parsing that exists in modern protobufjs (6.x+) but does not exist in version 2.2.1's architecture. Version 2.2.1 uses a fundamentally different parsing approach with linear token advancement and immediate validation, which prevents inf..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b840fcc6-b99d-57c3-88de-6d83aa98ac17",
      "id": "GHSA-4gpv-cvmq-6526",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4gpv-cvmq-6526 is a false positive for protobufjs 2.2.1-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1722e90-b28d-5645-9c77-da3844fbd772",
      "id": "GHSA-v2p6-4mp7-3r9v",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2p6-4mp7-3r9v is fixed in version 2.2.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@2.2.1-tuxcare.1"
    }
  ]
}