{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b1b6a699-5bc3-533a-b566-be6844950f1f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1",
      "type": "library",
      "name": "@next/mdx",
      "version": "12.3.7-tuxcare.1",
      "purl": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0bdacf54-54d6-5bef-b450-af6051b042aa",
      "id": "AIKIDO-2025-10854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10854 is fixed in version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a978373-99eb-55d4-953b-f36b7ff28308",
      "id": "CVE-2023-46298",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46298 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0982a1c-b4a2-529c-9512-ea7b16b3c357",
      "id": "CVE-2024-34351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34351 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09837090-10c1-514d-a28c-f1bda05a3e57",
      "id": "CVE-2024-47831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47831 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:627bc9df-6ca1-56d7-9f3b-472629b7ef5b",
      "id": "CVE-2025-59472",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-59472 does not affect version 12.3.7-tuxcare.1 of @next/mdx. not_affected \u2014 Next.js 12.3.7-tuxcare.7 is not affected by CVE-2025-59472. The vulnerability requires Partial Prerendering (PPR) functionality, which was introduced in Next.js 14 and does not exist in version 12.3.7. The vulnerable code path\u2014specifically the PPR resume endpoint that accepts POST requests with the Next-Resume header and processes postponed state data\u2014is entirely absent from this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:202d6c61-bb9a-5e5e-8793-990693a65a68",
      "id": "CVE-2026-44572",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44572 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ab4aad0-7744-58c5-b410-f20cd80df6b1",
      "id": "CVE-2026-44573",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44573 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f2d68e-b839-5355-b592-cd233e72d7f5",
      "id": "CVE-2026-44577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44577 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e887239-6072-548c-9674-0dc435051e1e",
      "id": "CVE-2026-64645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64645 affects version 12.3.7-tuxcare.1 of @next/mdx."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40next/mdx@12.3.7-tuxcare.1"
    }
  ]
}