{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1c820d5e-092a-5007-9fa4-2abf8259fbeb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.27.2-tuxcare.4",
      "type": "library",
      "name": "axios",
      "version": "0.27.2-tuxcare.4",
      "purl": "pkg:npm/axios@0.27.2-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:12e1e60b-929a-53fd-9309-ee1967e6df64",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a9898b-34b3-51a3-b459-2749607038a2",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.27.2-tuxcare.4 of axios. Version 0.27.2 is not vulnerable. Summary: The target repository (axios 0.27.2-tuxcare.1) is NOT vulnerable to CVE-2024-39338. It uses the legacy url.parse() API instead of the vulnerable new URL() constructor with hardcoded 'http://localhost' base. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:306cecd0-61c1-5a58-b57f-c1c82a9ebb02",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4849b87a-199c-5bd3-9060-555e39b0fb2e",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4295bb22-8dd1-5e6d-9974-70a76540ff6c",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19185f48-b8a0-582b-a09d-b8e62f49a6f7",
      "id": "CVE-2026-39865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39865 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:840e5e8d-234a-5f66-ab96-65a2e593dfa1",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea01c9c-28dc-57a5-bfdd-5b88bf95b079",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b937623-e8bb-54f0-a993-19286fac95e1",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fb4f3af-77be-5b9b-be3f-fd38a7ccfab2",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:086fa1f2-e88b-5c12-bfff-034b7fa76dac",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23338277-fcb1-53c3-b364-45c80a6aafea",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acde0265-975c-56df-ac42-3aba406e38d6",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc5c8cd8-f8f2-5b0c-8226-81776d1c512a",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c59d696-ae5a-51a0-ad40-fdef3b0e3f8a",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961b81f8-2119-594d-9536-d7e20894bd76",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d10cce4-22c0-56f4-a25d-609122b17d70",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2be7f271-b9fd-5a54-a5ed-1999e27a8e5d",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da658586-d673-5e20-af16-12e21c47bb0b",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1daa038-bd1c-5959-a891-e8799156e65c",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b809987b-e94a-5413-a6f7-b2020fa9a28c",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:189760e0-7162-5990-a6eb-58e365b9e54c",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef5d502a-cc14-5d3b-afb7-7b7b5fd61d4c",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71eb7b73-f713-5d7b-ba68-eb0762cc8a71",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cccf50b8-14bb-5b8b-80cd-7035e0a7961b",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.27.2-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.27.2-tuxcare.4"
    }
  ]
}