{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:aab744d9-0329-5431-b439-e57dec749351",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/undici@6.11.1-tuxcare.2",
      "type": "library",
      "name": "undici",
      "version": "6.11.1-tuxcare.2",
      "purl": "pkg:npm/undici@6.11.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:57f79edf-0b22-55b2-8d1b-f1ee9f24fc1c",
      "id": "CVE-2025-22150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22150 is fixed in version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4440968f-c13b-535b-b420-71b23f7d5ffa",
      "id": "CVE-2025-47279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47279 is fixed in version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4304229f-78c0-50bb-80c4-89ff1d5080d9",
      "id": "CVE-2026-11525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-11525 affects version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5430dbef-d94c-5fb3-85ea-93e6a9f855e1",
      "id": "CVE-2026-12151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12151 affects version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bcdfe9d-f186-50ba-996c-1b6e215aa8aa",
      "id": "CVE-2026-1525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1525 affects version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58cff984-c0dc-5739-b9a5-dfedb1e05423",
      "id": "CVE-2026-1526",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1526 does not affect version 6.11.1-tuxcare.2 of undici. not_affected \u2014 Version 6.11.1 is not affected by CVE-2026-1526. The permessage-deflate WebSocket extension is explicitly disabled in this version and no decompression code exists. The vulnerable feature was only added in later version 6.18.0 (commit 5a564bd9)."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42a64d23-5ebf-5487-8eca-a462738a86dc",
      "id": "CVE-2026-1527",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1527 affects version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8467c88c-7dc9-5727-9b42-1c3981e31d99",
      "id": "CVE-2026-1528",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1528 affects version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39520894-1598-5cd5-8986-182cb8ead21a",
      "id": "CVE-2026-22036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22036 is fixed in version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:305a86d7-1a43-5274-b69d-8635149f3b49",
      "id": "CVE-2026-2229",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2229 does not affect version 6.11.1-tuxcare.2 of undici. not_affected \u2014 The target repository (undici v6.11.1) does not have the permessage-deflate WebSocket extension implemented. The vulnerable code does not exist in this version. The extension was added later in v6.18.0 (commit 5a564bd9, May 2024), while the target is an earlier version where permessage-deflate is explicitly disabled."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935549c0-8bc3-5b27-a1c2-8aec83d82a7d",
      "id": "CVE-2026-6733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6733 affects version 6.11.1-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:953f6473-abbb-5dc2-bd39-5a52d9959137",
      "id": "CVE-2026-9679",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-9679 does not affect version 6.11.1-tuxcare.2 of undici. not_affected \u2014 Target version 6.11.1 does not contain the vulnerable code pattern. The vulnerability (percent-decoding of cookie values via qsUnescape) was introduced in undici 7.0.0 via PR #3789. Version 6.11.1 predates this change and does not perform any percent-decoding of cookie values, returning them as-is. Without the decoding transformation, percent-encoded sequences like %0D%0A remain as harmless lit..."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/undici@6.11.1-tuxcare.2"
    }
  ]
}