{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e7dc2238-3de4-5e73-939b-cda888347c62",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "fast-uri",
      "purl": "pkg:npm/fast-uri@2.4.3",
      "type": "library",
      "bom-ref": "pkg:npm/fast-uri@2.4.3",
      "version": "2.4.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-16221",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:95c3ff21-1b86-5df2-a9d2-dd7b2b3a9aab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-16221 affects version 2.4.3 of fast-uri."
      }
    },
    {
      "id": "CVE-2026-18446",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:e08d77ed-74d7-5f90-8ba3-dc8d867a34eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-18446 affects version 2.4.3 of fast-uri, and is fixed in 2.4.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-6321",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:e04dca99-1d3e-5899-b43e-85cc1362af46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6321 affects version 2.4.3 of fast-uri."
      }
    },
    {
      "id": "CVE-2026-6322",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:6f23de6a-df1e-54ad-9498-8e939ccf3df7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-6322 does not affect version 2.4.3 of fast-uri. not_affected \u2014 CVE-2026-6322 is NOT present in fast-uri v2.4.3. The vulnerability (percent-encoded authority delimiter decoding causing authority structure changes) has been mitigated by upstream vendor fix in commit 23108bc, which introduced the reescapeHostDelimiters() defense. This fix was authored by Matteo Collina (upstream fast-uri maintainer) and backported to the 2.4.x line in fast-uri v2.4.1, prior t..."
      }
    },
    {
      "id": "CVE-2026-75899",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:6c7c813a-e7a9-5e01-b778-349a7fb24980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75899 affects version 2.4.3 of fast-uri, and is fixed in 2.4.3-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-75931",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:4e8b9089-4da2-5ac0-9f46-fabfbc8f4569",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75931 affects version 2.4.3 of fast-uri, and is fixed in 2.4.3-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-75975",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:e9ef48cd-60c8-5326-962d-5fae94180ba9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75975 affects version 2.4.3 of fast-uri, and is fixed in 2.4.3-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-76172",
      "affects": [
        {
          "ref": "pkg:npm/fast-uri@2.4.3"
        }
      ],
      "bom-ref": "urn:uuid:25de111b-15da-5de5-964d-2987eaa3b08b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-76172 affects version 2.4.3 of fast-uri, and is fixed in 2.4.3-tuxcare.2."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/fast-uri@2.4.3"
    }
  ]
}