{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:40775d83-ef6a-572a-84e8-e1d20b70de10",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.6.8-tuxcare.4",
      "type": "library",
      "name": "axios",
      "version": "1.6.8-tuxcare.4",
      "purl": "pkg:npm/axios@1.6.8-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a13351ab-beba-5fed-9fb2-23b7fec2b294",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39338 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25f0d513-11be-5f53-a5e1-4159ccd6ee54",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-27152 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2025-27152 fix already exists in commit 22c2e77ccde46e0a3c0d1513b682eba8dfb41d75"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:533deb7d-8c59-5c8b-977f-db341ed1d7ff",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-58754 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2025-58754 fix already exists in commit fe89d8c609e567fa731f7677ab065742330f25ea"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd4210f6-eb1d-5b98-9134-eb68c14afda9",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2025-62718 fix already exists in commit dd333bdabf51d856d0d14fe7bd9d50ac817e4aa2"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1022c3d4-1c34-5f52-a5a8-621dfb8fe5f7",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-25639 fix already exists in commit f4e3c49872deb794ae9a7bb71a8345ea2ec4b6eb"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad5f20b4-471e-5a2b-8229-d46accf69fed",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40175 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-40175 fix already exists in commit e3c915c5421c511d667ffeace65d8d65829e19e8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0858547-1c22-55f7-b4b6-eff98e27e8e8",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42033 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42033 fix already exists in commit 9c513d377d64d936e51eb33b901bb6a26258abd8"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7543465-52b3-57f7-b54b-d26bcb8bd9ff",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42034 fix already exists in commit cd256b069536974eeec07e8047ceeb87986d19bc"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:084cc21a-5aa7-55eb-85c5-e9f89bdb3497",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42035 fix already exists in commit b9e4e1b49f5f62215e46c059f343b2e9ccb81c39"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a05b58-9b45-5d6e-82bc-2aa2e2a9fbbd",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42036 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42036 fix already exists in commit db7082ebbf0cf245e8d001407b789a154606afac"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b24f3f3-62ff-563e-ad89-93cc08949d8c",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb4aef87-a6c1-54d0-b702-215b24ab2b8c",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42038 fix already exists in commit 38fbaef2676858fc97ea981cf9e2fabf343e60a4"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02e91b9a-2495-5ef8-b99b-6607626def72",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42039 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42039 fix already exists in commit da36cba07a133fa5f833556303db0e3e5ce3dc87"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eea308f-3bbd-53d2-b45a-bb1ec38cd27a",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06a6bc5f-b160-5c58-9427-a761a662c7bf",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42041 fix already exists in commit 935b8c002f9b50ff36d4f0ed3b6be5fc855a0b6e"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b46e5e-8a18-55e2-b7bf-3b67f193a626",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42042 fix already exists in commit be54ef4e740e14b267e765f8e42ff9104d78bc8b"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eca4dcb-3abb-56d3-9ed2-805fdc2ae423",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.6.8-tuxcare.4 of axios. CVE-2026-42043 fix already exists in commit 2a6288f317a7bfc46a41088a3809a22e8193340a"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1675b6df-b1f5-5481-bef2-a4fe953902ca",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8d4ce5-3df3-5496-b932-90cd2243353c",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dae8651-d8f9-5560-b1f9-405f721d91f5",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9789572-9161-547c-806d-61b6815592f2",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fe99d46-14c3-5b1f-bf98-771c49741493",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b257dfc-eaa2-5e9d-aeff-ce6c04d98278",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 1.6.8-tuxcare.4 of axios. not_affected \u2014 axios v1.6.8 is not affected by CVE-2026-44492. The vulnerable code (lib/helpers/shouldBypassProxy.js) was introduced in v1.15.0, and v1.6.8 predates this entirely. The target uses a different architecture (proxy-from-env only) that is outside the scope of this CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ba9d751-f8c1-579c-951e-5dd4c1ff135c",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44494 affects version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c9480cd-108f-52a9-bfa3-e3ab23220faa",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df06a87c-fcf6-588b-8159-4d8111ada746",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba623796-317f-5eee-abe8-86e1f5479ada",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07eadae2-7542-58ca-990f-d5fb93c36c5b",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a973039a-b113-5178-a195-80313afdfdae",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02fa1e60-8c1a-572e-be3a-900a5186a4df",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.6.8-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.6.8-tuxcare.4"
    }
  ]
}