{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e913dc2b-baaf-57e3-934a-c3315d5d5617",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2",
      "type": "library",
      "name": "protobufjs",
      "version": "6.11.6-tuxcare.2",
      "purl": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1aabfd5e-422c-5b0b-94c5-42972cdd9202",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc8938e-a7d7-5a7f-803a-082d70641a12",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44288 is fixed in version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:728c3778-d6df-5ad3-a4e4-bda7a0f8a41a",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44289 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9008341b-3d44-5342-819d-6b5bb0ef2929",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44290 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95dfe510-3232-53ec-9052-f9d8599aaa2d",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44291 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05bf743-a6f6-500a-ad0a-5a5501e0cd50",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44292 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cad5baa-a745-5bcf-aaf5-9f49bd99eb90",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44293 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f995495f-44b4-5252-a15f-9601221ef52d",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44294 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95fa66c7-1690-55ab-9625-54e33b1689bd",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45740 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda8033d-fb62-53cc-b3fd-72df7de5a587",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48712 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39467d17-b569-5e17-aea4-5e5ac674b55f",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.11.6-tuxcare.2 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c14855-14fc-5b1e-8e08-8485e5deb8ce",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.11.6-tuxcare.2 of protobufjs. not_affected \u2014 The target repository (protobufjs 6.11.6-tuxcare.3) is NOT AFFECTED by CVE-2026-54270. This vulnerability was introduced in version 8.2.0 when unknown field preservation was added. Version 6.11.6 simply discards unknown fields during decoding without storing them, which is semantically equivalent to the patched behavior (discardUnknown = true). The vulnerable code pattern (preserving unknown fi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884888f4-4254-53ea-abe4-e227bc748227",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.11.6-tuxcare.2 of protobufjs. not_affected \u2014 CVE-2026-59876 requires the optional Text Format extension (ext/textformat.js) for exploitation. The target version 6.11.6-tuxcare.4 does not have this extension, which was only introduced in upstream protobuf.js v8.2.0 (May 2026). The target cannot parse text format protobuf messages and therefore cannot receive the vulnerable input (text-format map entries with __proto__ keys)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c54b0479-4845-5521-bce1-43a9eb50e5b6",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.11.6-tuxcare.2 of protobufjs. not_affected \u2014 Target version 6.11.6 uses a fundamentally different option parsing architecture that predates the introduction of the vulnerable while loop. The vulnerability affects protobufjs v8.x where option parsing was refactored to use a while loop without EOF validation. Version 6.11.6 uses IF-based parsing with explicit skip() calls that throw errors on EOF, preventing any infinite loop condition."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@6.11.6-tuxcare.2"
    }
  ]
}