{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:67411bf1-09f7-5377-987c-f360691d6ab4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@6.2.1-tuxcare.3",
      "type": "library",
      "name": "tar",
      "version": "6.2.1-tuxcare.3",
      "purl": "pkg:npm/tar@6.2.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5f97d3ed-25b1-57ff-a67b-fa12066bdccd",
      "id": "CVE-2024-45296",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45296 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ae30c3f-139e-5378-9e64-3b15869be245",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f920ea-b3b6-5109-a2b8-fada2051948e",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f6f027c-355d-56e5-9255-a9a584610813",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6509e807-a767-58ef-9b3a-521e53fef704",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad98a77-8eff-5ad8-a7d8-c15efdd2a618",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29786 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5ae06e-2026-5b6b-bd0a-d53f77c13615",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31802 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de3ebe81-747a-5ace-ad27-e85159c4d723",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53655 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f442e00c-e7b7-5b75-86e3-8335940b715e",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59871 affects version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef879996-a944-57b5-9ea7-6588193afb77",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59873 affects version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb129bd1-912a-5745-b44c-4911aa9d8502",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59874 affects version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8165240f-6e08-5966-a447-de891f54352e",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59875 affects version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ca01966-1f72-5135-9ab8-e40c2173c672",
      "id": "GHSA-qffp-2rhf-9h96",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-qffp-2rhf-9h96 does not affect version 6.2.1-tuxcare.3 of tar. already_fixed \u2014 The target repository (tar 6.2.1-tuxcare.3) already contains a backport of the vendor fix for GHSA-qffp-2rhf-9h96. The fix was applied in commit 4b41989e on March 13, 2026, which backported CVE-2026-29786 (the CVE identifier corresponding to GHSA-qffp-2rhf-9h96). The defense strips drive-relative root prefixes (like 'C:') from paths BEFORE checking for parent directory traversal sequences ('..')."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4596263-d2a2-50c4-acfd-3fd152252942",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r292-9mhp-454m affects version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
    }
  ]
}