{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ba4abc7b-57d9-578b-a4e9-8829b14c4e7e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "1.5.1-tuxcare.1",
      "purl": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:13ecfdd0-6a07-5ae2-8ee1-517bb78c840c",
      "id": "CVE-2018-20835",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-20835 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e921d16a-d6db-5e8f-a5ce-db5324ad9518",
      "id": "CVE-2018-3738",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3738 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63f96f2a-e92c-51ed-b71e-585764c5a0bc",
      "id": "CVE-2021-31597",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-31597 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f64eab2c-6654-5456-a185-3e619609958d",
      "id": "CVE-2024-12905",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12905 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e7eb157-a087-5703-87d1-c0dabcffa95b",
      "id": "CVE-2025-48387",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48387 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac6ec17c-95d2-54d2-b5f2-dc5e183c5013",
      "id": "CVE-2025-59343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59343 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:174676d2-dcc6-5c88-b0ba-9d82b1d754e2",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9c8a5e-371a-5591-b662-ac6ef58f3eaa",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44288 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 is not affected by CVE-2026-44288. The vulnerable code (protobufjs's minimal UTF-8 decoder in lib/utf8/index.js or src/util/utf8.js) does not exist in this version. Version 1.5.1 uses a completely different architecture, delegating all UTF-8 encoding/decoding operations to the ByteBuffer.js library (v~2.0) via methods like readVString(). The minimal UTF-8 decoder that contains the..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a4549c-da9e-5aec-b0af-7fba692b746b",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86df7ed8-e5aa-5830-b6e8-d145bff93c92",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 is not affected by CVE-2026-44290. The vulnerability requires option path traversal features (setParsedOption, parsedOptions) present in modern protobufjs versions 6.x/7.x but absent in this 2013-era version. Version 1.5.1 has a fundamentally different architecture and does not parse or traverse dotted option paths."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4d46ac8-a7f7-5bc7-9f2b-09a9cfa72d17",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44291 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 is not affected by CVE-2026-44291. While this version uses plain objects for type lookups and does not have the specific protections added in the upstream patch (Object.create(null), __proto__ filtering), it employs a fundamentally different architecture with comprehensive regex validation that acts as an alternative defense, preventing polluted prototype properties from enabling ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d84dc82a-2830-5359-90f2-672dda37c8cb",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44292 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 is not affected by CVE-2026-44292. While it processes plain JavaScript objects with properties, the reflection-based architecture provides an alternative defense that prevents __proto__ injection. The init function validates all property keys against the message schema via the set method, which rejects unknown keys including __proto__ before any assignment occurs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af226605-d9b5-53a3-8fd9-9266e76e4a23",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44293 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Target version 1.5.1 is not affected by CVE-2026-44293. The vulnerability exists in protobuf.js v7.x's code generation for toObject conversion when processing JSON descriptors with malicious bytes field defaults. Version 1.5.1 uses a completely different architecture: it only accepts .proto text files (not JSON descriptors) and uses runtime reflection instead of code generation. The vulnerable ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1f28fa5-12ec-5603-9e54-38116d5ddbbe",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44294 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 of protobufjs is not affected by CVE-2026-44294. This CVE concerns a code generation vulnerability in modern protobuf.js (7.x/8.x) where field names containing control characters are embedded into statically generated JavaScript code without proper escaping, causing syntax errors. Version 1.5.1 uses a completely different architecture: (1) it validates all field/message/enum names..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b652409-bbea-539e-89a9-c4f7d6604ea8",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68003602-dbea-512f-ba97-bfa2b761dfcb",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48712 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 CVE-2026-48712 targets unbounded recursion in toObject() JSON conversion and google.protobuf.Any wrapper functions specific to protobuf.js 6.x/7.x architecture. The target repository (protobufjs version 1.5.1) uses a fundamentally different architecture that lacks these conversion mechanisms entirely. Version 1.5.1 only supports binary protobuf encoding/decoding without any JSON or plain object..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:645b2d47-c003-5c35-8039-11dc1560817b",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54269 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 protobufjs 1.5.1 uses a fundamentally different architecture from the vulnerable protobufjs 8.5.0. The vulnerability patterns described in CVE-2026-54269 (hasOwnProperty shadowing, rpcCall shadowing, and $-prefixed name collisions) do not exist in the legacy 1.x codebase."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:662c0793-52fb-533b-b031-d2a32e2bc3d2",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 does not implement the vulnerable feature. The CVE states 'protobufjs 8.2.0 added support for preserving unknown fields' - this feature was introduced years after version 1.5.1 was released. The target's decode logic discards unknown fields by design (Reflect.js:754-773), preventing the memory accumulation vulnerability. This behavior is semantically equivalent to the fix (discard..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98e33f10-5661-53fc-9823-7cc5c823bc35",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 is not affected by CVE-2026-59876. The vulnerability targets the protobufjs Text Format extension (ext/textformat.js) and proto3 map fields, both of which were introduced in version 6.x+ (circa 2016). Version 1.5.1 (released 2013) predates proto3, has no ext/ directory, no text format extension, and no map field support. The vulnerable code path does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01406ecd-e397-579b-92f4-23ca6291446b",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 1.5.1-tuxcare.1 of protobufjs. not_affected \u2014 Version 1.5.1 does not contain the vulnerable code pattern described in CVE-2026-59877. The infinite loop vulnerability was introduced in later versions (6.x+) when option parsing was refactored to use a while loop. Version 1.5.1 uses a different architecture with sequential token advancement and immediate validation."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a321bb4b-3135-56a9-ad9a-1839c5d13000",
      "id": "GHSA-4gpv-cvmq-6526",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4gpv-cvmq-6526 is a false positive for protobufjs 1.5.1-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f37cbb-f9eb-5cd0-8848-42126f355fff",
      "id": "GHSA-c7pp-x73h-4m2v",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c7pp-x73h-4m2v is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6d82fc5-9762-50df-a7a3-9df216cd4354",
      "id": "fix-test-env-compat",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability fix-test-env-compat is fixed in version 1.5.1-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@1.5.1-tuxcare.1"
    }
  ]
}