{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13ceba89-faae-58a3-b0eb-83abddecdaa5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@6.2.1-tuxcare.4",
      "type": "library",
      "name": "tar",
      "version": "6.2.1-tuxcare.4",
      "purl": "pkg:npm/tar@6.2.1-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d453a2a0-1bb1-5724-869b-73aed27cf6f7",
      "id": "CVE-2024-45296",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45296 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05d7ca3b-1eec-5e43-a2c5-2b3f93ba387f",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175c79fa-8e7a-54da-9ee8-e19099f6a490",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e075115-3fe9-5f9f-ae09-6aa5332cd8ad",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:570f8c25-f805-53a2-b455-c157e4f26ece",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5723ba2e-4ae9-5cf2-87f6-37635589d0aa",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29786 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10af53ba-17b1-528e-99f3-77f2bf158a6b",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31802 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:438aa74f-a942-5349-aa2e-92a0654cc8e0",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53655 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b688f6d-6b8e-5b31-8aa5-0ab19a2185f1",
      "id": "CVE-2026-59871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59871 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5926b085-6a16-5160-8272-2255516b40c5",
      "id": "CVE-2026-59873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59873 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44eaab05-7b68-5e92-8d35-37e567110c45",
      "id": "CVE-2026-59874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59874 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf4b2b86-9fe2-5f33-8f22-faea71aaeb06",
      "id": "CVE-2026-59875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59875 is fixed in version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce610d42-3ef7-575a-bf9e-03684e713a96",
      "id": "GHSA-qffp-2rhf-9h96",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-qffp-2rhf-9h96 does not affect version 6.2.1-tuxcare.4 of tar. already_fixed \u2014 The target repository (tar 6.2.1-tuxcare.3) already contains a backport of the vendor fix for GHSA-qffp-2rhf-9h96. The fix was applied in commit 4b41989e on March 13, 2026, which backported CVE-2026-29786 (the CVE identifier corresponding to GHSA-qffp-2rhf-9h96). The defense strips drive-relative root prefixes (like 'C:') from paths BEFORE checking for parent directory traversal sequences ('..')."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce03e8b9-0bc7-520d-855b-1ddacc59c41f",
      "id": "GHSA-r292-9mhp-454m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r292-9mhp-454m affects version 6.2.1-tuxcare.4 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@6.2.1-tuxcare.4"
    }
  ]
}