{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4667a825-c8ff-5218-9771-f5ecec9113d4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.7.9-tuxcare.3",
      "type": "library",
      "name": "axios",
      "version": "1.7.9-tuxcare.3",
      "purl": "pkg:npm/axios@1.7.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:933e1488-abc8-5b6f-8c0a-520d6df2b1cf",
      "id": "CVE-2020-7676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7676 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48b9e7d0-1e70-511f-99c1-dd7f37b97e28",
      "id": "CVE-2022-25844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25844 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06857da-56dc-530f-bf7f-a253ef8bf50e",
      "id": "CVE-2022-25869",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25869 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a50b28c0-9b8f-5a17-9c4e-f7c0778a5bfd",
      "id": "CVE-2023-26116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26116 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7111e65-cf5a-5ade-ad47-3a08e511b610",
      "id": "CVE-2023-26117",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26117 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29db6724-a4d4-5d5f-9306-5a6d028b308b",
      "id": "CVE-2023-26118",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26118 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:347ae07f-81e5-5509-b5b2-c51c463bfbb4",
      "id": "CVE-2024-21490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21490 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cda67d4-bdcd-5f7c-922c-393aa33a2753",
      "id": "CVE-2024-8372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8372 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02e6ef40-4d66-5a35-8d16-33e29d3b25d6",
      "id": "CVE-2024-8373",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8373 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518df4eb-9a75-53e1-b0b0-d01c32a8c313",
      "id": "CVE-2025-0716",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-0716 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2715b58a-8622-54f8-9928-cbe4e8c6bf2a",
      "id": "CVE-2025-2336",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-2336 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8e191d4-a020-57b1-9297-b45d70de47d5",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e29b122-5cea-5346-bb30-701c88c50e89",
      "id": "CVE-2025-4690",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-4690 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e841d3-c965-521b-bbf7-36b1bb555578",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94fdfd9b-cf90-5695-ac62-bc3dce6fc5ce",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf59fd0f-7cbe-5503-a670-3eb6c4b41be5",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.7.9-tuxcare.3 of axios. Version 1.7.9 is not vulnerable. Summary: The target repository (axios v1.7.9) is NOT vulnerable to CVE-2026-25639. The target uses Object.assign({}, config1, config2) for key iteration, which does not include __proto__ in Object.keys() results, preventing the DoS crash. The vulnerable code pattern was introduced later in v1.11.0 when the code was refactored to use the spread operator ({...config1, ...config2}). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2939a9c8-a25b-5714-abd8-c3ff007de5d1",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c25452-915a-58d6-87cf-be1f93f7f03a",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386a1d0c-ff38-5197-a510-c68277046977",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:815b68e6-c5c6-5446-bd94-c33a59bba601",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3f866d2-10db-595f-8060-d95445566c2b",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cfb6e5-7bc5-52f7-b544-c5b458b373e0",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4df9fc58-bbdf-5dc9-890a-1c590726ab88",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4418ca0-f269-582d-90c8-4b144bef9715",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b75f7d-256f-524b-bcaa-f4ef31d9456f",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:075ae727-c6ed-5548-a9d7-236e9ce5f2b2",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8581d889-22cf-5366-93f8-3d9a83c65b39",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1203ef93-85ac-5c8f-bbff-47065f31a318",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.7.9-tuxcare.3 of axios. Version 1.7.9 is not vulnerable. Summary: The target version (axios v1.7.9) is NOT vulnerable to CVE-2026-42043 because the vulnerable shouldBypassProxy feature does not exist in this version. The target uses the external 'proxy-from-env' package for proxy handling, whereas the vulnerability exists in axios's own shouldBypassProxy implementation that was only introduced in version 1.15.0. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec4268e-b221-5234-96f6-8220b2ef6ff1",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff51a77-33a4-5c9b-b3fd-4ca9dc27e65f",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0ee6bce-f6c8-5cb7-86cf-7c6f78037c23",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:486d9ebc-c81f-548a-b2e5-ac8517c4576e",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fe0d9a3-d8cf-547b-94af-aaddb9fbb6fd",
      "id": "CVE-2026-44488",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44488 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8544765b-a636-56cd-922a-011af29762a8",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2408adf-934b-58f5-9c6c-bccce1d6f579",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d200315-33de-5ecf-a5e0-91c29f28bba6",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44494 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4a481fb-eb47-5504-8179-4de0c3ce92c9",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44495 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:475a1e7e-2368-5f5d-ac5d-2b774d6e24c3",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:898b98ce-7af7-596c-9b09-138871e8b8bb",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f0dcb79-4017-51ae-a9da-e076c0899ca5",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2570602-b463-5dd5-85b2-544d7739d8e4",
      "id": "GHSA-jqh4-m9w3-8hp9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jqh4-m9w3-8hp9 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50dfafb1-d2e9-5f9f-9fa7-7891e6c1db73",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c316bc0c-4321-58c2-8e9a-6df18ca092b2",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 is fixed in version 1.7.9-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.7.9-tuxcare.3"
    }
  ]
}