{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:acb41273-d829-5724-9372-f9e12417dedc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5",
      "type": "library",
      "name": "@astrojs/rss",
      "version": "3.6.5-tuxcare.5",
      "purl": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4c29a033-4c46-5d8d-a0f9-678c2c390cde",
      "id": "CVE-2024-47885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47885 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e010beb-5baf-5adb-91da-a0867103aa21",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff7d15aa-85d0-5864-a278-adeef991e967",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dec6bc8-f6e1-5213-91e3-3032fb5d8fc9",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72ff863-3063-5bf8-90d9-395dc61bc803",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6455c606-4f4b-59da-9600-2344d4c41bd0",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8846743b-e8af-54d7-adac-6957e18783bc",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1af846a3-8b98-589c-9901-37e4e1b1ca2d",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51da488-d61f-50f8-b926-cb8a4578ff81",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a6475d-6229-53fb-91a6-6d278e66e240",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d432fbbf-8623-56dc-bfe8-46b7c2864447",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:016d4207-27c0-525b-9cca-c3d29e1e164b",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a897cae9-bc99-55f6-9327-b166fea1078f",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479a6074-1e92-59a5-9103-995df7131017",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 3.6.5-tuxcare.5 of @astrojs/rss. not_affected \u2014 Astro version 3.6.5 is NOT AFFECTED by CVE-2026-45028. The vulnerability concerns server islands encryption (AES-GCM ciphertext replay between props and slots), but server islands functionality does not exist in version 3.6.5. The feature was introduced in later versions (~May 2025, v5.x/6.x), and the vulnerability was fixed in v6.1.10 (April 2026). Exhaustive search across 327 source files con..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b18cb5c-e3d8-533c-8861-5cb48a0deb93",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e3e7db-db6e-5869-b910-70884e1a911b",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa4e954-b1d9-5469-a92f-1f7fea8157a1",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54299 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27db8aa6-223f-512e-87de-2e4a06a6714b",
      "id": "CVE-2026-59728",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59728 is fixed in version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7a86902-5a5c-5b19-9f56-f8aaecde1668",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e48d3187-b0f4-5f23-ac6c-28dcce7c9b33",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b2bdf6a-3161-581b-adc4-88e6c6cabdcb",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 3.6.5-tuxcare.5 of @astrojs/rss."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/rss@3.6.5-tuxcare.5"
    }
  ]
}