{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:32ddf739-a9de-5921-981f-7a445e43076d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.18.1-tuxcare.4",
      "type": "library",
      "name": "axios",
      "version": "0.18.1-tuxcare.4",
      "purl": "pkg:npm/axios@0.18.1-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cd89e101-5c6b-55dc-9c32-ffbd723b07ad",
      "id": "CVE-2020-28168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28168 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d91578-7f4e-5358-aba2-d8555e5a9e2c",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7906e1d-da83-5ff1-b9d6-27c68c2d36b9",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dd14b03-86e0-534b-ab83-f18afd749cf2",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39338 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46c4dbf2-b1d6-5787-bff6-f8cdef6c9f84",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62c3c96b-77d4-5f78-89eb-000314c0ef1d",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07338a65-b811-5467-adf1-980115dfff8c",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c59cab-5795-51cc-b2bf-06735229f3e1",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba18cb03-e9b6-5d09-80af-11fac5b91b5b",
      "id": "CVE-2026-39865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39865 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2b191b9-8137-5873-aa20-5b24caeb8dd9",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d589ad8e-16be-5d42-a3d6-6a28987595dc",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29566570-1962-5488-b07b-e70a7b2f5b36",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b90f182-e3ca-5cae-b3c7-e61f5e5ad970",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b59dbdd-9e28-5a69-92af-ba8bfa60188d",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1bd7b0a-9e6d-52c3-8ca7-0319060fdc00",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a24d6a-813d-5f79-8256-e86c23e406d4",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36ce93c6-5f96-58f0-8072-c9f09aa7076b",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aa10777-cf01-596e-8159-d722d501bf13",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54d9039-6bcc-5119-8f26-80cd5e260971",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76f0040a-ea72-5002-8bd6-6598e197f9a2",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b407520-fea4-54d2-a88a-219a6b32bc47",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44486 does not affect version 0.18.1-tuxcare.4 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44486 (Proxy-Authorization header leak on redirect). The fix was backported in commit 806a27b (also 3a086d9 in a backport branch), which implements the exact same defense as vendor commit afca61a070728e717203c2bc21e7b589b59b858b."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8cdb9af-321a-55f3-ac0e-97ff0a2257cf",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44487 does not affect version 0.18.1-tuxcare.4 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44487 (GHSA-j5f8-grm9-p9fc). The exact vendor commit afca61a070728e717203c2bc21e7b589b59b858b was backported in commit 806a27b as part of CVE-2024-28849 remediation on April 28, 2026. The defense mechanism strips stale Proxy-Authorization headers on redirect re-invocations, preventing credential leakage to unintended recipients."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f78dbf2-07b4-5591-b297-035c172437b9",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395cccc7-8095-5760-b587-cb3a0a5d53fa",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 0.18.1-tuxcare.4 of axios. not_affected \u2014 The target repository axios v0.18.1-tuxcare.2 does not implement NO_PROXY functionality at all. The vulnerability CVE-2026-44492 is specific to shouldBypassProxy.js (introduced in v1.15.0) which handles NO_PROXY hostname comparison. Since v0.18.1 predates this feature and has no hostname comparison or bypass logic, the vulnerability pattern cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d947b90-c3ad-5aa9-ad9c-baa171f8aac5",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c23938e9-511b-5bf2-93ef-dfe7f18ab75e",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9ee7912-ad14-5f06-9f59-2d3ef4608a17",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.18.1-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.18.1-tuxcare.4"
    }
  ]
}