{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:32830bb4-e217-571b-9030-63cfeed0f235",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4",
      "type": "library",
      "name": "@astrojs/telemetry",
      "version": "1.9.2-tuxcare.4",
      "purl": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3e1f88f8-9eba-54f4-86c6-62d0e2a6b82c",
      "id": "CVE-2013-7370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2013-7370 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99e4db6-b213-5a46-9c83-f62bcf948ce6",
      "id": "CVE-2013-7371",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2013-7371 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e3cbd3-6bb1-5e12-abe1-3a46df29ee67",
      "id": "CVE-2018-3717",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3717 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e60aeb-204a-5b56-a6d4-f11eee74b93a",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da8f2cff-c8f9-5098-8526-150b72973bda",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4402b87c-9bd8-56bd-90be-4c9b16e6f274",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad02c1ea-70d9-5afe-9c66-8dcfc4c046ac",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad3ca137-8da5-5adc-a6d3-3213df4c5e1b",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6974ac-425e-53a7-8e97-e5737a61d8cf",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1747a2ad-a86e-5d61-868b-8c6b0b9cbf27",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3acf1a-bb3c-54cd-b36f-ad57e7d49b4c",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea248625-4ed9-556d-ae4f-047c229773f7",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0612b947-675a-5772-9e31-f65c1b3cacf1",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:236fcba3-89f4-5d7b-9ab2-2f4ed9fc5bd1",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 1.9.2-tuxcare.4 of @astrojs/telemetry. not_affected \u2014 Astro version 1.9.2 is not affected by CVE-2026-45028. The vulnerability concerns server islands, a feature that encrypts component parameters (props, slots, componentExport) using AES-GCM without binding ciphertext to component/parameter context, allowing replay attacks. However, the server islands feature does not exist in version 1.9.2. This feature was introduced much later (PR #11305) in A..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf48ea9d-4d54-577e-a482-62f9233f4309",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a332a68c-e97b-5275-a740-79730e448530",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c6b82b-8b40-5be7-86ec-a76b3a880f37",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 1.9.2-tuxcare.4 of @astrojs/telemetry. not_affected \u2014 Astro version 1.9.2 is not affected by CVE-2026-54299. The vulnerability requires the prerendered error page HTTP fetching feature, which was introduced in Astro 5.12.9+. Version 1.9.2 renders all error pages in-process using the component system, not via HTTP fetch, eliminating the SSRF attack vector."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12bcb1c-e000-528b-ae9c-8247171d67d5",
      "id": "CVE-2026-59728",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59728 does not affect version 1.9.2-tuxcare.4 of @astrojs/telemetry. not_affected \u2014 Version 2.0.0 of @astrojs/rss does not support the `source` or `enclosure` fields mentioned in CVE-2026-59728. These features were added in a later version (between 2.0.0 and 4.0.19), and the vulnerability was introduced with those features. The current version cannot process RSS feed items with `source.title` or `enclosure.type` fields, making the XML injection vulnerability described in the C..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:773248e8-70a5-5bc6-b0c2-16fb39b4d0c8",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 1.9.2-tuxcare.4 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae32930e-0d63-5f59-bee3-5aa91ecdcea6",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-73422 does not affect version 1.9.2-tuxcare.4 of @astrojs/telemetry. not_affected \u2014 Astro version 1.9.0 is not affected by CVE-2026-73422. The View Transitions feature\u2014which contains the vulnerable code path where animation property values are embedded in generated CSS without escaping\u2014does not exist in this version. View Transitions were introduced in Astro 2.9 (mid-2023), while version 1.9.0 is from late 2022. The vulnerable file `packages/astro/src/runtime/server/transition..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f92c9e62-98f4-5f54-b563-5c2f57a1f43a",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 does not affect version 1.9.2-tuxcare.4 of @astrojs/telemetry. not_affected \u2014 Astro version 1.9.2 does not contain View Transitions functionality. The vulnerable code path (packages/astro/src/runtime/server/transition.ts) does not exist because the View Transitions feature was introduced in a later version (around Astro 2.9+). The vulnerability requires View Transition animation properties to be processed and embedded in generated CSS, but this entire feature is absent f..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/telemetry@1.9.2-tuxcare.4"
    }
  ]
}