{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af138950-d379-5741-8a21-38a3a6885f22",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9",
      "type": "library",
      "name": "@nuxt/vite-builder",
      "version": "3.12.4-tuxcare.9",
      "purl": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c98f3e9c-5b5e-5703-b3a5-4e1ae569b867",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/vite-builder 3.12.4-tuxcare.9. CVE-2022-25852 is a wrong-project match. The advisory concerns pg-native and libpq (PostgreSQL client libraries for Node.js), but the target repository is Nuxt.js version 3.12.4-tuxcare.9, a Vue.js web application framework. The Product-Identity Check found no connection between the projects: (a) target identity is Nuxt.js per package.json and README; (b) advisory product is pg-native/libpq; (c) exhaustive containment search found zero occurrences of pg-native or libpq as the project itself, as vendored/bundled code, or as declared dependencies. No native addons or PostgreSQL-related code exists anywhere in the repository."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79240b9-934c-57ac-be17-0895d1135a36",
      "id": "CVE-2025-24360",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24360 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95d24e0b-e324-5103-a963-557964c9e32b",
      "id": "CVE-2025-24361",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24361 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff18fb53-b533-586e-b988-7c31e527a732",
      "id": "CVE-2025-27415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97e513ed-a106-5a82-9f08-7f78de559a9f",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58751 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:202d3417-1d99-5884-9e6f-2c2094b84018",
      "id": "CVE-2025-59414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59414 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df034a37-7b23-52fa-96e0-6fb3dd0926f1",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00f56140-9e8e-52a1-bf42-30621ba47055",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41305 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:779bbba6-d60c-55ff-8455-f14cf0c41004",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/vite-builder 3.12.4-tuxcare.9. false_positive \u2014 CVE-2026-42338 is a false positive match for this repository. The CVE concerns the 'ip-address' npm package (specifically XSS vulnerabilities in the Address6 class), but this repository is 'nuxt' (Nuxt.js web framework version 3.12.4-tuxcare.5). Exhaustive search confirmed that the ip-address package is not present in this repository as the project itself, as a vendored/bundled copy, or as a de..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bba66e-a8ec-5dd2-a9dd-bc46a3266dfb",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bde4f9e0-8633-5070-ad7d-d9c4a0e5f2f7",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794c3cc7-c720-5e7f-9b15-67b8bc37eb51",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47200 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:372e163b-0859-5d6f-b283-94cf999ae8d8",
      "id": "CVE-2026-53721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53721 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dfdcea6-827d-51dc-a7ef-88ab79215bd0",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2065a704-a048-59b3-b1cc-f9da04c9285d",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56326 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd08c44-beb5-5793-9cb0-af78898a0018",
      "id": "CVE-2026-71314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50042260-64f3-5743-bed4-463aa88c69a7",
      "id": "CVE-2026-71316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 3.12.4-tuxcare.9 of @nuxt/vite-builder. Nuxt version 3.12.4 is NOT affected by CVE-2026-71316. The vulnerability is specific to Nuxt 4.4.0-4.5.1 and relies on runtime payload caching architecture introduced in Nuxt 4.x. In version 3.12.4, the payload cache mechanism is tied to `import.meta.prerender` and designed exclusively for build-time static site generation, not runtime request caching. The vulnerable code path that returns cached payloads before middleware execution is not reachable in normal production deployments of Nuxt 3.x because the cache is only populated during prerendering and contains static data, not user-specific SSR data. Between versions 3.12.4 and 4.4.0, Nuxt underwent a major architecture change (renderer.ts was removed/relocated, and a new runtime caching system was introduced) that fundamentally altered how payload caching works."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d925c2-8188-5bcb-9967-ce92f73d4066",
      "id": "CVE-2026-71318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0cd8b9-c333-56d3-891a-fb6e2fc9238f",
      "id": "CVE-2026-71320",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71320 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf37211f-2f78-59ba-8684-a8b463a384e5",
      "id": "CVE-2026-71321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e86b68-ac44-5803-bbee-5e2cb4f08d70",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 is fixed in version 3.12.4-tuxcare.9 of @nuxt/vite-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e798fbd7-0496-5f17-aab8-f6fbaa844d30",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.12.4-tuxcare.9 of @nuxt/vite-builder. not_affected \u2014 Target version (nuxt@3.12.4-tuxcare.5) is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerability was introduced 1754 commits AFTER v3.12.4 when Nuxt upgraded from unhead v1 to v2 in v3.16.0. The target uses a fundamentally different, older implementation that does not contain the vulnerable innerHTML pattern."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/vite-builder@3.12.4-tuxcare.9"
    }
  ]
}