{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b4a9575a-ecf8-55d2-a890-0c138ce3d7bf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@6.2.1-tuxcare.2",
      "type": "library",
      "name": "tar",
      "version": "6.2.1-tuxcare.2",
      "purl": "pkg:npm/tar@6.2.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7f3e3bb8-18b5-5389-9633-995fce5200ed",
      "id": "CVE-2024-45296",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45296 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5050417-3d1d-50d4-b533-cf2a0515f31c",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45941c4-262b-5cf0-98fb-f3706d30cc0c",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9295ff1-f959-5bbf-b9f5-4f8b1c214558",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ef5b8a2-7b63-56b7-a749-aebbb5cff549",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82d5c14-efc3-51ae-aae6-eaf2cd4fe8bb",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29786 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f42532-be86-5693-9a1d-c5360c15c5e6",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31802 is fixed in version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49385040-6f3c-5ac3-bfea-a3e52e04649e",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53655 affects version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ed66cb1-a96a-54de-96b3-d7eef56b6419",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59871 affects version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d5375c-3788-5870-9d5a-886dcc904740",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59873 affects version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad63a925-cd67-5d9a-846e-8fcc909d8f2c",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59874 affects version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ced1e24-6357-5a9a-8c49-7ad71bd12ccb",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59875 affects version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01275916-16b9-521f-afb7-262d0288b62e",
      "id": "GHSA-qffp-2rhf-9h96",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-qffp-2rhf-9h96 does not affect version 6.2.1-tuxcare.2 of tar. already_fixed \u2014 The target repository (tar 6.2.1-tuxcare.3) already contains a backport of the vendor fix for GHSA-qffp-2rhf-9h96. The fix was applied in commit 4b41989e on March 13, 2026, which backported CVE-2026-29786 (the CVE identifier corresponding to GHSA-qffp-2rhf-9h96). The defense strips drive-relative root prefixes (like 'C:') from paths BEFORE checking for parent directory traversal sequences ('..')."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5585f8a9-28e0-550f-933c-821d5784eb67",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r292-9mhp-454m affects version 6.2.1-tuxcare.2 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@6.2.1-tuxcare.2"
    }
  ]
}