{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fd1a4980-1384-5957-a4dd-54fe46647fbc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@2.2.2-tuxcare.1",
      "type": "library",
      "name": "tar",
      "version": "2.2.2-tuxcare.1",
      "purl": "pkg:npm/tar@2.2.2-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:56e49ae5-feae-56ec-b5e8-d868770bebdd",
      "id": "CVE-2016-1000232",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2016-1000232 is a false positive for tar 2.2.2-tuxcare.1. false_positive \u2014 CVE-2016-1000232 concerns the tough-cookie HTTP cookie parsing library, but the target repository is node-tar, a TAR archive file processing library. This is a wrong-project match with no containment relationship."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6038249b-e990-5051-9140-72dad6f65e89",
      "id": "CVE-2017-15010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-15010 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39cb33e4-f200-54c1-bbdf-abb3a74294fe",
      "id": "CVE-2021-32804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32804 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a52f3020-8a67-5a9a-9b92-c95500a9ee0f",
      "id": "CVE-2021-37713",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37713 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b72780fa-6489-5d30-bec2-c5d85fb885a0",
      "id": "CVE-2023-26136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26136 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efc1b14e-c8d4-5b72-b4c6-b38794180b7d",
      "id": "CVE-2024-28863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28863 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dcad791-ac3b-5e67-877a-069de756e724",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b3289b-1079-58db-8da2-0b02d54d691f",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c239f3-0d43-5473-a827-9f65a2e42db2",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9c3beb-2f80-5435-a830-a616164f0b20",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696ecc5d-071c-5317-9da4-98abe45a10f2",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29786 affects version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49a0f0e-bdad-57fb-bf1c-1e913566b4ed",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31802 affects version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:992291d7-3bd3-5fd0-927c-e7c913d8329e",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53655 does not affect version 2.2.2-tuxcare.1 of tar. already_fixed \u2014 Version 2.2.2 is not vulnerable. The target contains an equivalent defense that prevents PAX extended header field overrides (especially size) from being applied to metadata headers (GNU long-name L, long-link K, PAX x/g). While the implementation differs from the upstream patch due to architectural differences between v2.2.2 and v7.x, the semantic protection is equivalent."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31fb0a43-2017-5a39-9c35-5fbfa2ccaf7c",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59871 does not affect version 2.2.2-tuxcare.1 of tar. not_affected \u2014 Version 2.2.2 is not affected by CVE-2026-59871. The vulnerability exists in newer versions where PAX header parsing unconditionally coerces all-digit string values to numbers. In version 2.2.2, the code only converts values to numbers when the field is explicitly listed in the 'numeric' object, which does not include 'path' or 'linkpath'. Therefore, even if a PAX header contains an all-digit p..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aac1bd5e-7f56-5fae-a745-c888cfb24d8e",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59873 affects version 2.2.2-tuxcare.1 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:597a826e-3143-58ca-90bf-b798950f5ba8",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59874 does not affect version 2.2.2-tuxcare.1 of tar. not_affected \u2014 Target version 2.2.2 does not have the tar.replace() API that contains the vulnerability. The replace() API was introduced in version 3.x or later, well after this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e74879-261c-525f-8a04-16a72dd75517",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59875 does not affect version 2.2.2-tuxcare.1 of tar. already_fixed \u2014 The target repository (node-tar v2.2.2) already contains an effective defense against CVE-2026-59875. While the target's extended header parser (lib/extended-header.js) does not strip NUL bytes at parse time (matching the vulnerable pre-fix pattern described in the CVE), a unified NUL-stripping defense exists downstream in lib/entry.js lines 165-169 that sanitizes ALL path and linkpath values (..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e424dd05-2494-594b-9c27-da30224bd08e",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-r292-9mhp-454m does not affect version 2.2.2-tuxcare.1 of tar. not_affected \u2014 Version 2.2.2 is not affected by GHSA-r292-9mhp-454m. The vulnerability exists in the `filesFilter` / `mapHas` functionality in src/list.ts of version 7.x, which enables member-selection filtering when calling tar.t() or tar.x() with a file list. Version 2.2.2 has a fundamentally different architecture (JavaScript-based streaming parser) that predates the TypeScript rewrite and does not contain..."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@2.2.2-tuxcare.1"
    }
  ]
}