{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb0c8c98-1ce2-5a4d-9914-dc1aabade5d5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@2.2.1-tuxcare.1",
      "type": "library",
      "name": "tar",
      "version": "2.2.1-tuxcare.1",
      "purl": "pkg:npm/tar@2.2.1-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a780e763-1141-5f22-9d67-725ceb49a90c",
      "id": "CVE-2018-20834",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20834 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea65e8d3-dae7-5c81-916d-276a636ccaac",
      "id": "CVE-2018-3738",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3738 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293cf8c9-4afd-5b29-9783-2bd13689f68f",
      "id": "CVE-2020-26311",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-26311 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6b1cfe1-12c9-5136-aa19-3694f96b19a7",
      "id": "CVE-2021-32804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32804 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6a4b49c-da67-586b-887e-0b8f0b5dd9b4",
      "id": "CVE-2021-37713",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37713 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db351dc8-0ba9-5dc5-9513-796c5284e413",
      "id": "CVE-2024-28863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28863 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9a4b706-ed0d-5d9e-834b-3edaeaf30f3f",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-23745 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb605347-e023-5e30-a9b3-3f65528c6390",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-23950 does not affect version 2.2.1-tuxcare.1 of tar. Version 2.2.1 is not vulnerable. Summary: CVE-2026-23950 does NOT affect node-tar v2.2.1-tuxcare.1. The vulnerable PathReservations system and normalize-unicode functionality were introduced in v7.0.0 (April 2024) during the TypeScript refactor. The target repository version 2.2.1 predates this by several major versions and uses a completely different, synchronous extraction architecture that is immune to the race condition described in this CVE. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b501a737-4c69-578b-bc81-1a42079393cb",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24842 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55b05d01-cdf1-5523-bb67-b9b84c03830e",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26960 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc57b380-2fe1-51ce-a2bb-1c6402a3787a",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29786 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0278e87b-c83f-5c2f-9a65-e1175aa18cab",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31802 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09618333-7edc-59fb-bf63-0b69f80032ae",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8689a117-61c8-593f-b839-2e684dc44ea6",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44290 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f6a4b39-dc64-582a-833a-9871e087bc90",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44291 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c228521-7e82-55fb-9e94-dcf9039b8c98",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44294 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e487ff-a552-5e4d-ba1a-a66aa69c7d56",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c91810-ce7c-53ef-8aa4-deac41d753cf",
      "id": "CVE-2026-46625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46625 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d03e5fa-d486-5cde-ae2c-0c02cc5b92b3",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c98289-7074-58bb-a9d7-f643c822d02f",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53655 does not affect version 2.2.1-tuxcare.1 of tar. already_fixed \u2014 Version 2.2.1 contains an equivalent defense that was original to the codebase (2011). The architecture differs from vulnerable upstream 7.x, but achieves the same protection: PAX extended header overrides are not applied to meta entries (GNU L/K, PAX x/g), preventing stream desynchronization. The defense at parse.js:231-232 nullifies extended/global parameters for meta entries before Entry cre..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293ab6fd-48ea-5159-a2d8-d0a7d2ae8b3a",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54269 is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:997a01ba-e3c4-5f77-84ab-4fd08677dd1f",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59871 does not affect version 2.2.1-tuxcare.1 of tar. not_affected \u2014 Version 2.2.1 is not affected by CVE-2026-59871. The vulnerability requires indiscriminate type coercion of all-digit PAX header path values to numbers, a behavior introduced in later TypeScript versions. Version 2.2.1 uses field-specific type conversion that explicitly excludes path and linkpath fields from numeric conversion, preventing the TypeError crash described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b863415-aa60-59e6-a299-f030e47b2933",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59873 affects version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95ff0a4f-c088-505d-888e-e9910072b784",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59874 does not affect version 2.2.1-tuxcare.1 of tar. not_affected \u2014 Version 2.2.1 does not contain the tar.replace() API that is the subject of CVE-2026-59874. While the underlying code can parse negative base-256 encoded entry sizes without validation, the specific attack mechanism (infinite loop from zero net position progress during archive scanning) requires the replace() function which was introduced in later versions of node-tar. The existing Parse module..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e06f62-3cb3-511b-91f7-6f40bd85a333",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59875 does not affect version 2.2.1-tuxcare.1 of tar. already_fixed \u2014 Version 2.2.1 is not vulnerable to CVE-2026-59875. The target contains a defense that strips NUL bytes from path and linkpath fields in lib/entry.js (lines 166-170), added in commit 0444d88 by isaacs on Nov 7, 2011. This unified sanitization point protects against NUL bytes from ALL sources including PAX extended headers, GNU long-name headers, and regular headers, preventing the uncaught excep..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f26a0b7-57ca-5f8d-954c-5d7ec6fe8ce3",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-r292-9mhp-454m does not affect version 2.2.1-tuxcare.1 of tar. not_affected \u2014 Version 2.2.1 is not affected by GHSA-r292-9mhp-454m. The vulnerability requires member-selection filtering (tar.t([members]) or tar.x([members])) which triggers recursive parent-directory traversal via mapHas. Version 2.2.1 has a fundamentally different architecture: it uses JavaScript (not TypeScript), has a lib/ directory (not src/), and provides only tar.Parse() and tar.Extract(opts) APIs w..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc886e2a-7917-51c4-af05-d9814a1be844",
      "id": "GHSA-v2p6-4mp7-3r9v",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2p6-4mp7-3r9v is fixed in version 2.2.1-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@2.2.1-tuxcare.1"
    }
  ]
}