{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:048fa152-1617-589a-a839-0db0f7a58277",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2",
      "type": "library",
      "name": "@nuxt/webpack-builder",
      "version": "4.0.3-tuxcare.2",
      "purl": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a62fe471-c9ad-54f6-925e-25f3116a0cef",
      "id": "CVE-2022-21670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-21670 is fixed in version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d269b9be-fdaa-5631-ab6a-36d43062f4c7",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/webpack-builder 4.0.3-tuxcare.2. CVE-2022-25852 concerns pg-native and libpq (PostgreSQL client libraries for Node.js), but the target repository is Nuxt (a Vue.js meta-framework). Exhaustive containment search found no pg-native/libpq code, no vendored copies, and no dependency relationships. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67400d8f-6681-5c5a-a0f3-ec8acaccd2d4",
      "id": "CVE-2025-59414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59414 is fixed in version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f7045f1-fcfc-5890-9f7b-76025cc237d1",
      "id": "CVE-2026-25128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25128 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd16a21-b025-5cd9-8e85-76ef56847a04",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc37dfe2-08b8-5265-988a-81a9eaa61592",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/webpack-builder 4.0.3-tuxcare.2. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm package, but this repository is the 'nuxt' framework. The affected component (ip-address library) is completely absent from the repository - not as the project itself, not as vendored/bundled code, and not as a declared dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96bcb516-8fc5-5cb6-8f1c-394a2484238e",
      "id": "CVE-2026-44372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44372 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a103c12-f854-5832-ad6b-51f2ac9b1d01",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45669 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96329a93-da9d-5a75-bf4b-0cdfcd95c395",
      "id": "CVE-2026-45670",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45670 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b523af0-6a6d-5906-be5f-1f7638dabc96",
      "id": "CVE-2026-45736",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-45736 is a false positive for @nuxt/webpack-builder 4.0.3-tuxcare.2. false_positive \u2014 CVE-2026-45736 is a wrong-project match. The advisory concerns the 'ws' WebSocket library for Node.js, but the target repository is Nuxt.js framework. The ws library's source code (specifically lib/sender.js containing the vulnerable WebSocket close implementation) does not exist anywhere in this repository. While ws appears as a transitive dependency in pnpm-lock.yaml, no ws source code is pre..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e0b1064-076f-50fa-9405-52b0ca16a3d3",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6315f008-4879-584c-a589-70de58fb4dc1",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47200 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e36fba6-8921-51d7-be8c-bd328aa342af",
      "id": "CVE-2026-49993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49993 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b23c871-0a00-5e54-b111-3e6eba501708",
      "id": "CVE-2026-53721",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53721 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f837134c-d1ab-54cf-beb4-e7a00a0ab3b8",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65581bd9-22d0-5692-a411-1b36b69ca137",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56326 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f9cfea-7d39-529a-89fe-db1ae5f2b889",
      "id": "CVE-2026-71314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b92cef-a286-5faf-91e6-5713b0ff32b6",
      "id": "CVE-2026-71316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 4.0.3-tuxcare.2 of @nuxt/webpack-builder. Version 4.0.3 is not affected by CVE-2026-71316. The CVE explicitly states the vulnerability was introduced \"From 4.4.0 until 4.5.1\", and the target version (4.0.3) predates this introduction. While the target does handle `_payload.json` requests and has prerender caching mechanisms, the specific vulnerability pattern that allows runtime cache bypass of middleware/guards was introduced in version 4.4.0 and does not exist in version 4.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:689ffcaf-5e5f-52cd-bf7c-7588fea99e9a",
      "id": "CVE-2026-71318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebd30eac-9e00-598c-9b63-a3b7b748d08b",
      "id": "CVE-2026-71320",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71320 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3e2250b-1615-547f-9e51-89ce6bb87c53",
      "id": "CVE-2026-71321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e969e7e4-ae5c-5f7b-ab91-db29360df638",
      "id": "GHSA-534h-c3cw-v3h9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-534h-c3cw-v3h9 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c89488cd-83a7-5658-a6cd-262754fceb26",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e6aac3f-9556-58c8-990b-97345c9abd6a",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a396a5-0314-590e-b984-7da563b4a4c2",
      "id": "GHSA-rq7w-g337-39qq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rq7w-g337-39qq affects version 4.0.3-tuxcare.2 of @nuxt/webpack-builder."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/webpack-builder@4.0.3-tuxcare.2"
    }
  ]
}