{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9a1eeb23-d06a-53ea-a992-41af5b5852f3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/multiparty@2.2.0-tuxcare.1",
      "type": "library",
      "name": "multiparty",
      "version": "2.2.0-tuxcare.1",
      "purl": "pkg:npm/multiparty@2.2.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:10c224b0-b4ce-534c-bf8d-9bfa285250f8",
      "id": "CVE-2016-1000232",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-1000232 is fixed in version 2.2.0-tuxcare.1 of multiparty."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f28601f2-f13a-5f66-ac96-d68d41dfe87a",
      "id": "CVE-2017-15010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-15010 is fixed in version 2.2.0-tuxcare.1 of multiparty."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61050edd-0cfc-59f5-a601-21714abb92ff",
      "id": "CVE-2017-16137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16137 is fixed in version 2.2.0-tuxcare.1 of multiparty."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a61f32-0a4d-5942-8942-28417cee906b",
      "id": "CVE-2017-20165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20165 is fixed in version 2.2.0-tuxcare.1 of multiparty."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:994c168b-25fe-5199-8d75-2b65f12cc20d",
      "id": "CVE-2023-26136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26136 is fixed in version 2.2.0-tuxcare.1 of multiparty."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:357deae3-8c4c-50bb-9cb6-28e92801c9d5",
      "id": "CVE-2026-8159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8159 is fixed in version 2.2.0-tuxcare.1 of multiparty."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6006703e-73e2-57d7-b8d9-577317e974b6",
      "id": "CVE-2026-8161",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8161 does not affect version 2.2.0-tuxcare.1 of multiparty. not_affected \u2014 Version 2.2.0 is NOT affected by CVE-2026-8161. The vulnerable code pattern (calling .push() on fields[name] where name could be an inherited Object.prototype property) does not exist in this version. The vulnerability was introduced 10 days after version 2.2.0 was released, in commit 81e6e2b (Oct 25, 2013). Version 2.2.0 uses a different implementation with direct property assignment instead o..."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef093f68-f261-5e5f-bffb-8955aded384e",
      "id": "CVE-2026-8162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8162 does not affect version 2.2.0-tuxcare.1 of multiparty. not_affected \u2014 Version 2.2.0 is NOT affected by CVE-2026-8162. The vulnerability affects the handling of malformed percent-encoding in RFC 2231 `filename*=utf-8''` headers, which causes an uncaught exception when `decodeURI` is called without try/catch. However, version 2.2.0 does not contain any code to parse `filename*=utf-8''` headers. This feature was introduced AFTER 2.2.0 in commit 8835716 (Nov 2013) an..."
      },
      "affects": [
        {
          "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/multiparty@2.2.0-tuxcare.1"
    }
  ]
}