{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bab32dfb-f56f-539a-a740-717312ede975",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5",
      "type": "library",
      "name": "@astrojs/db",
      "version": "5.18.1-tuxcare.5",
      "purl": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ce2b4c1b-2b50-580f-a04e-c3e63dc3b316",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-55303 does not affect version 5.18.1-tuxcare.5 of @astrojs/db. not_affected \u2014 The target repository (astro@5.18.1-tuxcare.5) is NOT affected by CVE-2025-55303. The vulnerability (protocol-relative URL bypass of domain restrictions) has been fixed by upstream commit 4d16de7f95, which is included in the base astro@5.18.1 release. The fix modifies the isRemotePath() function to detect URLs starting with '//' as remote paths, subjecting them to domain authorization checks. W..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7a42f3a-1c97-5cf0-a2e4-9e47858a5a0d",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58751 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8249c8d-61c6-51ce-a9b1-7e5ff313b4e2",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dafba700-48ea-55b8-b4f7-f1c9eddcba81",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a5b8f67-6a18-52df-a625-e872646cef14",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45028 affects version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:429da3ae-ba41-59d0-a6dd-98202a91c82a",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50146 does not affect version 5.18.1-tuxcare.5 of @astrojs/db. already_fixed \u2014 The target repository (astro v5.18.1-tuxcare.3) already contains the vendor's slot name XSS fix. The escapeHTML() function is applied to slot names at both injection points (lines 348 and 362 in component.ts) before interpolating into HTML attributes, preventing attribute context breakout attacks. The fix was backported by TuxCare's automation service on May 18, 2026 via commit b30fca309f."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55383b3d-095e-5f5e-a1d3-4fedb6cff9b1",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:502116f9-b0bd-59f6-a35c-18b3ec8e6d84",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:440b25d3-4d07-5b27-909c-0e1741f4ce7e",
      "id": "CVE-2026-59727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59727 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:311ea1fa-c6b5-5065-806c-d21de91e9d1d",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59729 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b151029b-51ff-54bb-ad7a-072790b7f8dd",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b38fc56-22d1-5f6e-abd5-7803105021e4",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 is fixed in version 5.18.1-tuxcare.5 of @astrojs/db."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/db@5.18.1-tuxcare.5"
    }
  ]
}