{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a3c4ede8-aa84-5792-8ca3-bcd21914ed46",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/undici@5.28.5-tuxcare.1",
      "type": "library",
      "name": "undici",
      "version": "5.28.5-tuxcare.1",
      "purl": "pkg:npm/undici@5.28.5-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a2ec78b6-d953-5fe0-b2fa-63bf4a82b6b2",
      "id": "AIKIDO-2024-10065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10065 is fixed in version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a81f11-fcab-58b2-ad31-707ab00e249d",
      "id": "CVE-2024-24750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24750 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f81489-fb15-55e3-98f3-4ac6425ce52e",
      "id": "CVE-2024-24758",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24758 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b5c739-d0c5-5b38-9440-b0f58d0c11fc",
      "id": "CVE-2025-47279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-47279 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df04e575-31ac-576d-b345-3be66f23fc8c",
      "id": "CVE-2026-11525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-11525 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d455d18-b162-5268-a5ba-bc6a9667093d",
      "id": "CVE-2026-12151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12151 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfa14d6c-465e-5287-a694-8633739a42f0",
      "id": "CVE-2026-1525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1525 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19e29c1b-ede5-555b-b7bd-8462581db7ae",
      "id": "CVE-2026-1526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1526 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b46c87-7e45-5775-87c7-026f8009ef87",
      "id": "CVE-2026-1527",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1527 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bf80790-46e0-5a30-b895-8c1bd78c1591",
      "id": "CVE-2026-22036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22036 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd99edd-cc9e-5c7d-ae84-bb55322ea290",
      "id": "CVE-2026-2229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2229 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc6263e8-3b8f-5488-803a-b91b29f498ea",
      "id": "CVE-2026-6733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6733 affects version 5.28.5-tuxcare.1 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68f928d8-3fb9-5441-a526-8adcc8d6dd77",
      "id": "CVE-2026-9679",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-9679 does not affect version 5.28.5-tuxcare.1 of undici. not_affected \u2014 Target repository version 5.28.5-tuxcare.4 is not affected by CVE-2026-9679. The vulnerability was introduced in undici 7.0.0 via commit dac8e73d (PR #3789), which added percent-decoding of cookie values using querystring.unescape(). Git history analysis confirms this commit is NOT an ancestor of the target's current HEAD. The target's cookie parser at lib/cookies/parse.js has never contained p..."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/undici@5.28.5-tuxcare.1"
    }
  ]
}