{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2ba52831-5ae7-5501-8cda-53cb3e767141",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2",
      "type": "library",
      "name": "@astrojs/telemetry",
      "version": "4.16.19-tuxcare.2",
      "purl": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c1a861c6-cba5-5cff-bac4-828aa6dd4b6d",
      "id": "AIKIDO-2025-10879",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10879 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e29b79f-85f3-5719-bb34-03841edf81d4",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55303 affects version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bde9edfb-0f4b-5ed7-9276-162ce3f230a3",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff16c39-a657-5426-89bd-e46ae6c91cd5",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a790508-f453-5e76-a44f-92da33fcb11f",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ef2ddd6-aa07-5f40-9cc0-ebba33228a6b",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6cc24e8-54db-5df0-9c01-4bd1a1f8c283",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9039bc99-7443-5c49-b0c3-7e7e5cc756a6",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26957bdf-a852-5d46-a254-ea3708aa87e1",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1cea283-5fd4-54b6-bf13-745568145528",
      "id": "CVE-2026-33490",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33490 is a false positive for @astrojs/telemetry 4.16.19-tuxcare.2. false_positive \u2014 CVE-2026-33490 concerns H3 (a minimal HTTP framework), but the target repository is Astro (a website build tool). H3 is not present in this repository - no vendored code, no dependency, no imports. The only 'h3' references found are HTML heading components (<h3> tags), unrelated to the H3 framework."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27064738-e5f5-5649-a17a-1e85439371e6",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad7084b-fdf1-5099-a5a9-75a786f817e1",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdde75a1-c730-5345-8f57-bc1d0a538667",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 4.16.19-tuxcare.2 of @astrojs/telemetry. not_affected \u2014 Astro version 4.16.19 is NOT affected by CVE-2026-45028. The vulnerability requires encrypted slots and componentExport features that were introduced in later versions (between 4.x and 6.x). The target uses an older server islands implementation that only encrypts props\u2014slots and componentExport are sent unencrypted. This makes the cross-parameter-type replay attack described in the CVE (replay..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a080aa-2340-5fcc-9a1d-b74b361f5352",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50146 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7825160e-54c1-5328-ab21-5c99173b5c15",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32853f4-91d4-5bf4-8199-c8ee13da25f2",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 4.16.19-tuxcare.2 of @astrojs/telemetry. already_fixed \u2014 The target repository has already fixed this vulnerability via CVE-2026-25545 / AIKIDO-2025-10879 (May 7, 2026), which addresses the identical SSRF issue. The fix removes the prerendered error page fetching feature entirely, replacing it with direct SSR rendering. This is a more aggressive mitigation than the upstream's host validation approach."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb9a261-9d44-5181-9c0f-f7534033a6a5",
      "id": "CVE-2026-59727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59727 affects version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53451af2-13ba-59da-a285-b6e65bcd1fde",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc63830-c5de-5d2b-9e98-7dc2ea515f04",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73422 affects version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba3add1-e138-5b36-bdc1-3ce8dabd4ff2",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 affects version 4.16.19-tuxcare.2 of @astrojs/telemetry."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/telemetry@4.16.19-tuxcare.2"
    }
  ]
}