{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:88096773-eeeb-5bb6-b893-61e2d8370759",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@2.1.1-tuxcare.3",
      "type": "library",
      "name": "tar",
      "version": "2.1.1-tuxcare.3",
      "purl": "pkg:npm/tar@2.1.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cf905d59-03f7-574e-9ec0-a90189d99c9f",
      "id": "CVE-2015-8860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8860 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80198ddb-90c3-50ef-952c-5bb3e618dfa6",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:724b04b8-be5a-5126-8557-f787b49ae108",
      "id": "CVE-2017-20165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20165 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f11988-9920-58ee-8822-2b9ba86d8c55",
      "id": "CVE-2018-20834",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20834 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:309425d2-52e3-550d-9cd2-23b91af620b7",
      "id": "CVE-2020-28481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28481 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:246ad3f6-ce8e-5354-9c24-64ca46fa16b0",
      "id": "CVE-2021-32804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32804 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d7e4894-0a00-5701-be2b-8a828b71850a",
      "id": "CVE-2021-37713",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37713 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ed4a3ba-d8e0-5351-8819-23c101028c7c",
      "id": "CVE-2024-28863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28863 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:681bc56d-a21c-5161-9def-ead29c9d7d55",
      "id": "CVE-2025-38355",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-38355 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4795c15-cbe4-5da3-999a-458f52b04ecd",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4efd288-d98f-5639-9fcf-9e41bb4898d4",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6a2b45-f816-54ff-a6be-332a02c5dda7",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ec55a8-dec6-52ee-9b97-e7eaa21baa17",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0e92954-ecd9-5aae-bfdd-2dba06a30076",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29786 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f29c3be-739e-5343-9f24-e7c38c82de13",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31802 is fixed in version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72bd106e-c570-5ed8-bafa-277a96e6133a",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53655 does not affect version 2.1.1-tuxcare.3 of tar. already_fixed \u2014 The target node-tar version 2.1.1-tuxcare.3 already contains an equivalent fix for CVE-2026-53655. The defense was added in October 2011 (commit 604f2dd) and prevents PAX extended header field overrides from being applied to intermediary metadata entries (GNU L/K, PAX x/g). This is the same defense logic that the upstream patch re-introduces after the TypeScript rewrite."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba6d859e-fa82-50f9-8a1a-8e91610365f6",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59871 does not affect version 2.1.1-tuxcare.3 of tar. not_affected \u2014 Version 2.1.1 is not affected by CVE-2026-59871. The vulnerability requires PAX header path/linkpath values to be converted to numbers, but version 2.1.1 uses a whitelist-based approach that explicitly excludes these fields from numeric conversion. The vulnerable code pattern exists only in newer TypeScript-based versions of node-tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14bb4bee-a1ab-5806-8852-6591a3a9ac0b",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59873 affects version 2.1.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc8a1306-9aaf-50c6-938d-fc3ced7fdddf",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59874 does not affect version 2.1.1-tuxcare.3 of tar. not_affected \u2014 CVE-2026-59874 targets the tar.replace() function's archive scanning algorithm, which does not exist in version 2.1.1. This version only provides Pack, Parse, and Extract APIs. The vulnerability requires the specific scanning logic in replace() that computes position advancement as (entry_size + 512), resulting in zero net progress when entry_size is -512. Version 2.1.1's Parse stream uses a fu..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556d4aa6-8352-5a8e-897c-264b3f727fe4",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59875 does not affect version 2.1.1-tuxcare.3 of tar. already_fixed \u2014 CVE-2026-59875 describes a NUL-byte injection vulnerability in node-tar's PAX extended header parsing that causes process termination via uncaught exception. The target repository (node-tar v2.1.1-tuxcare.3) contains an effective defense against this vulnerability at lib/entry.js:165-169 that strips NUL bytes from path and linkpath fields before they reach filesystem operations, preventing the ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:013772cd-caf6-5460-9000-1e137a64ff2a",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-r292-9mhp-454m does not affect version 2.1.1-tuxcare.3 of tar. not_affected \u2014 Version 2.1.1 is not affected by GHSA-r292-9mhp-454m. The vulnerability requires a member-selection API (tar.t(options, members) or tar.x(options, members)) that installs a filesFilter containing a recursive mapHas helper. Version 2.1.1 has a fundamentally different architecture with only streaming APIs (Parse, Extract, Pack) and no member-selection capability. While version 2.1.1 does process ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@2.1.1-tuxcare.3"
    }
  ]
}