{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:696aa722-1349-5977-af91-a5ef4de348a9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "mysql2",
      "purl": "pkg:npm/mysql2@2.3.3-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/mysql2@2.3.3-tuxcare.1",
      "version": "2.3.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "AIKIDO-2026-10225",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d9aee649-21fd-59de-93d6-837bbc8ba854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2026-10225 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.3."
      }
    },
    {
      "id": "CVE-2024-21507",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bc40baa5-583e-5324-8753-bf0f3bf1704a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21507 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.4."
      }
    },
    {
      "id": "CVE-2024-21508",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0db93738-3e00-56ea-bd32-74ee7826501b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21508 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-21509",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54b3496e-ba52-5ec8-8e8d-af4f4283b231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21509 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-21511",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c1c2f378-7778-5d77-885d-c516092c3c9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21511 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-21512",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:14e1593b-4d3d-5955-a5bb-8bb63500971b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21512 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-3f6p-5ww8-9rcr",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:166c1061-7cca-5657-9ed7-9ac9f78a1c5c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-3f6p-5ww8-9rcr does not affect version 2.3.3-tuxcare.1 of mysql2. not_affected \u2014 Version 2.3.3-tuxcare.6 is NOT AFFECTED by GHSA-3f6p-5ww8-9rcr. The vulnerable mysql_clear_password authentication plugin does not exist in this version. The plugin was only introduced in v3.0.0-rc.1 (March 2022), well after v2.3.3 was released (November 2021). When a rogue server requests the mysql_clear_password plugin via AuthSwitchRequest, the library rejects it with error \"Server requests ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-rgwj-5xj2-c3m3",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ea68f53-a7b8-5146-aaab-d2a054373203",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rgwj-5xj2-c3m3 affects version 2.3.3-tuxcare.1 of mysql2, and is fixed in 2.3.3-tuxcare.6."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/mysql2@2.3.3-tuxcare.1"
    }
  ]
}