{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:22a89bc0-2142-5f58-bd6b-895aa6078687",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "mysql2",
      "purl": "pkg:npm/mysql2@2.3.3-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/mysql2@2.3.3-tuxcare.5",
      "version": "2.3.3-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "AIKIDO-2026-10225",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:368e68fd-3ae7-52fb-912f-09cac35aa7c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10225 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21507",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7380a41f-c18f-5d35-8546-c695304da251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21507 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21508",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:48bf41f0-4ae7-5058-97f1-6cace468c205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21508 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21509",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:356fb44a-13f4-5224-828f-91256183922b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21509 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21511",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c7d3b019-69d6-5dd7-bece-177e9594efc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21511 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21512",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3656cf59-f548-59ef-a0d5-4e513b4d500c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21512 is fixed in version 2.3.3-tuxcare.5 of mysql2."
      }
    },
    {
      "id": "GHSA-3f6p-5ww8-9rcr",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5fa9fee7-2fa4-5f42-9f5a-8a285db3d7c6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-3f6p-5ww8-9rcr does not affect version 2.3.3-tuxcare.5 of mysql2. not_affected \u2014 Version 2.3.3-tuxcare.6 is NOT AFFECTED by GHSA-3f6p-5ww8-9rcr. The vulnerable mysql_clear_password authentication plugin does not exist in this version. The plugin was only introduced in v3.0.0-rc.1 (March 2022), well after v2.3.3 was released (November 2021). When a rogue server requests the mysql_clear_password plugin via AuthSwitchRequest, the library rejects it with error \"Server requests ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-rgwj-5xj2-c3m3",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7ff3c4be-c6b5-5c20-8c08-f981855ce0c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rgwj-5xj2-c3m3 affects version 2.3.3-tuxcare.5 of mysql2, and is fixed in 2.3.3-tuxcare.6."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/mysql2@2.3.3-tuxcare.5"
    }
  ]
}