{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:aa84189a-b11a-5273-92dc-b0be3d9f7337",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5",
      "type": "library",
      "name": "@nuxt/schema",
      "version": "4.0.3-tuxcare.5",
      "purl": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e2ecf149-4ede-5a42-9dfb-8fdf37846020",
      "id": "CVE-2022-21670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-21670 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:385ccdec-9d7d-5f51-a1a2-df559be60c28",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/schema 4.0.3-tuxcare.5. CVE-2022-25852 concerns pg-native and libpq (PostgreSQL client libraries for Node.js), but the target repository is Nuxt (a Vue.js meta-framework). Exhaustive containment search found no pg-native/libpq code, no vendored copies, and no dependency relationships. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09ef89f-8eab-5588-b3a3-760454ee4cd6",
      "id": "CVE-2025-59414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59414 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d896541-858b-5ce1-92e8-99db68077b07",
      "id": "CVE-2026-25128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25128 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b31307ed-4204-56f4-8846-d09f23c5863f",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41305 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a93fdf-8893-5c25-bb0d-7fabf31775e4",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/schema 4.0.3-tuxcare.5. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm package, but this repository is the 'nuxt' framework. The affected component (ip-address library) is completely absent from the repository - not as the project itself, not as vendored/bundled code, and not as a declared dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b343ce9f-9913-51e9-8a64-5503b98ad843",
      "id": "CVE-2026-44372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44372 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83329c3a-2b9e-5335-a9dd-de2981cdbe61",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45669 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3227dc1-2a1b-5104-9736-8eac39da23fa",
      "id": "CVE-2026-45670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45670 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98edb5f0-e732-585d-8a6c-e57b00b2e4d3",
      "id": "CVE-2026-45736",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-45736 is a false positive for @nuxt/schema 4.0.3-tuxcare.5. false_positive \u2014 CVE-2026-45736 is a wrong-project match. The advisory concerns the 'ws' WebSocket library for Node.js, but the target repository is Nuxt.js framework. The ws library's source code (specifically lib/sender.js containing the vulnerable WebSocket close implementation) does not exist anywhere in this repository. While ws appears as a transitive dependency in pnpm-lock.yaml, no ws source code is pre..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39dfebfe-68f3-5b22-9936-8d9059afecfe",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46342 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1831d7c4-996e-58bf-826d-ac7e6bcbbb8b",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47200 affects version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9ec5b9-4ce9-58e7-a186-7a7252da5c73",
      "id": "CVE-2026-49993",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49993 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0629db7d-259c-5f42-b5ea-06e14ec14a09",
      "id": "CVE-2026-53721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53721 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b582d46b-6f9c-5d8a-b05a-6f8ba5f198ed",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5682bd9-0b3e-5849-9763-6344590625f3",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56326 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1faf0ea9-0c38-5608-bf86-8bf6d1fc7099",
      "id": "CVE-2026-71314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4072be2-2bc1-57dd-88ed-c0dcf8915a00",
      "id": "CVE-2026-71316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 4.0.3-tuxcare.5 of @nuxt/schema. Version 4.0.3 is not affected by CVE-2026-71316. The CVE explicitly states the vulnerability was introduced \"From 4.4.0 until 4.5.1\", and the target version (4.0.3) predates this introduction. While the target does handle `_payload.json` requests and has prerender caching mechanisms, the specific vulnerability pattern that allows runtime cache bypass of middleware/guards was introduced in version 4.4.0 and does not exist in version 4.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a46c35-6c0b-5e91-9549-6577bd4f5878",
      "id": "CVE-2026-71318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9024e1c3-4412-5f26-92a6-8d3ac77247a4",
      "id": "CVE-2026-71320",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71320 affects version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192f158f-b410-54b4-b338-a214b23e814e",
      "id": "CVE-2026-71321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d2f335a-52b9-5908-94d1-a4242060ec41",
      "id": "GHSA-534h-c3cw-v3h9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-534h-c3cw-v3h9 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:640f9203-7e9c-5838-95bd-ae4a7ec3e77f",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30db1215-b261-5609-8da4-3a0100813409",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m affects version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde4f577-25e7-5ebd-9d22-657e66180bd8",
      "id": "GHSA-rq7w-g337-39qq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-rq7w-g337-39qq is fixed in version 4.0.3-tuxcare.5 of @nuxt/schema."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/schema@4.0.3-tuxcare.5"
    }
  ]
}