{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b5ec2252-3a76-5a73-8750-708bdac264e4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "5.0.0-tuxcare.1",
      "purl": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8f512d66-c30d-5295-9d32-daa556423114",
      "id": "CVE-2018-3738",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3738 is fixed in version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39410338-30de-5411-b549-fda7b5595346",
      "id": "CVE-2021-23495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23495 is fixed in version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:791efe99-f677-57f6-bd29-cf5173ee6cda",
      "id": "CVE-2022-0437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-0437 is fixed in version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e43992d0-3d35-5fc8-a1fb-0519fd12ec5e",
      "id": "CVE-2024-29180",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29180 is fixed in version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01f029c7-ccf9-5ca7-bbca-d5c904973aa2",
      "id": "CVE-2026-24001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24001 is fixed in version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a98cdfe6-7410-5f02-a9e9-4227b13ed3f0",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41242 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09771032-ade0-5d48-b668-0e7d2fa3e846",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44288 does not affect version 5.0.0-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.0 is not affected by CVE-2026-44288. The vulnerability affects protobufjs's minimal UTF-8 decoder (@protobufjs/utf8 package) introduced in version 6.0.0+. Version 5.0.0 uses a fundamentally different architecture, delegating all UTF-8 encoding/decoding to the external ByteBuffer library (version ~5), which does not have this vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ed49ff-67dc-592c-8611-b6f381d56ed6",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44289 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2777ca89-2494-5565-9bb4-03f4951a4c97",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44290 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61f2a0c1-dabd-5850-bf95-009add2beba8",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44291 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e62ae2ff-bf54-592b-9a9d-bf91fe2e582f",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44292 does not affect version 5.0.0-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.0 is not affected by CVE-2026-44292. This version uses a fundamentally different architecture from the vulnerable versions (6.x/7.x): runtime message builders with field validation instead of code-generated static constructors. The field validation mechanism rejects unknown keys like '__proto__' by default, preventing prototype pollution in normal usage scenarios."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26fc5f7-38fb-506c-98b5-8d8fd2233350",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44293 does not affect version 5.0.0-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.0 is not affected by CVE-2026-44293. The vulnerability exists in the static code generation feature (src/converter.js) that generates toObject methods with unsafe string interpolation of bytes field defaults. This feature was introduced in version 6.4.0, and version 5.0.0 predates it entirely. Version 5.0.0 uses a Builder-based runtime architecture where message conversion (toRaw me..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1de26002-aa01-50c7-9385-76f2121a1c19",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44294 does not affect version 5.0.0-tuxcare.1 of protobufjs. not_affected \u2014 protobufjs version 5.0.0 is not affected by CVE-2026-44294. The vulnerability requires runtime code generation with field names embedded in JavaScript code strings, a mechanism that does not exist in version 5.0.0. This version uses a fundamentally different architecture with direct property access via bracket notation instead of dynamic code compilation."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011b903f-9dc8-54c0-88eb-2d538ce06ffb",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45740 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18831bbd-aa73-57bb-a500-d6df830a2880",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48712 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cf4261b-e032-5bb4-ab8f-257c49c1a9f2",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a799ff96-e238-5ff6-a8f0-c2dd53fb838b",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 5.0.0-tuxcare.1 of protobufjs. not_affected \u2014 protobufjs version 5.0.0 is not affected by CVE-2026-54270. The vulnerability concerns unknown field preservation introduced in version 8.2.0, a feature that does not exist in version 5.0.0. This version discards unknown fields by design, preventing the memory exhaustion attack described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5511933f-11df-5b42-8d0f-2116c3ae3203",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 5.0.0-tuxcare.1 of protobufjs. not_affected \u2014 protobuf.js version 5.0.0 does not contain the text format extension (ext/textformat) where CVE-2026-59876 manifests. The vulnerability specifically affects the optional text format parser, which was not present in version 5.x. All existing input paths in this version (binary decode, JSON, object construction) use safe property handling with Object.keys() or hasOwnProperty() checks, preventing ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8844ce04-adb5-5a22-87f1-4e604fc3300a",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59877 affects version 5.0.0-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e333465a-5d2e-5342-81ef-9f2d2c057f6c",
      "id": "GHSA-4gpv-cvmq-6526",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4gpv-cvmq-6526 is a false positive for protobufjs 5.0.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@5.0.0-tuxcare.1"
    }
  ]
}