{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cc3b195a-8878-5e1b-9125-65b3b460ee4c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.15.3-tuxcare.4",
      "type": "library",
      "name": "axios",
      "version": "0.15.3-tuxcare.4",
      "purl": "pkg:npm/axios@0.15.3-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cb32e406-28c0-5494-8050-cdbd710295da",
      "id": "CVE-2019-10742",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10742 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c9c0422-211c-5f39-be68-16b3551dd25a",
      "id": "CVE-2020-28168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28168 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcce07c7-488f-54c9-b60e-0ed8d8209170",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a408ef-08c4-5760-bb87-1f92f8dcb7ab",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bb2b15-26a3-55c1-a75f-3262deb54dd9",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39338 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f89ce2e-b70e-5d3e-8796-36c250c0e4ab",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75dff45e-9bc0-536e-970b-69cc1e35434a",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:222c85db-88b9-544f-a70b-88dc7a4d3e50",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c055f5-6ec4-5b7a-a099-78d72fcb86aa",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d049ec7-4eb9-52df-8149-0ce61b545001",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca245090-ea2a-5a2a-8a61-bdb192011731",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f645037c-75a7-5eaf-b30f-039ef7a2e079",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa15f9b5-2e0b-53e0-9910-40b4119f7b0d",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abacd952-ec59-58b1-9e5b-fc384464065f",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41fdcc71-b66b-548a-9348-4ade72b22fe9",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94457f63-cba4-5fd4-98c0-a60e89ee4d83",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42040 does not affect version 0.15.3-tuxcare.4 of axios. not_affected \u2014 Version 0.15.3 does not contain the vulnerable component lib/helpers/AxiosURLSearchParams.js, which was introduced in v1.0.0-alpha.1 (2022). The CVE describes a null byte injection vulnerability in the encode() function within AxiosURLSearchParams.js, specifically the charMap entry '%00': '\\x00' that reverses safe percent-encoding. This file and vulnerability pattern do not exist in 0.15.3. The..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03850438-bfa2-5455-b4e9-cfe7c8fb7933",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 0.15.3-tuxcare.4 of axios. not_affected \u2014 Version 0.15.3 is NOT AFFECTED by CVE-2026-42041. The vulnerability requires the mergeDirectKeys function (introduced in later axios versions ~1.x) which uses the `in` operator to check property existence, allowing prototype chain traversal. Version 0.15.3 uses a fundamentally different architecture: utils.merge() with a hasOwnProperty filter that has been present since the initial implementati..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c077f36a-031b-5e36-b8dd-323758583bd9",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 0.15.3-tuxcare.4 of axios. not_affected \u2014 Axios version 0.15.3 is NOT affected by CVE-2026-42042. The vulnerability targets the `withXSRFToken` configuration property, which was introduced in versions after 0.15.3. This version uses a different XSRF implementation based on the `withCredentials` property (introduced in v0.8.1 per CHANGELOG). The vulnerable code component (lib/helpers/resolveConfig.js) and the `withXSRFToken` feature are..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:592bfad7-02c5-5c52-8248-22314a7ca3d3",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf7cdd8-0b4a-5958-af21-0ce6843284ce",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29105906-bdb8-5f85-a0b5-1e42871d46d1",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44487 does not affect version 0.15.3-tuxcare.4 of axios. not_affected \u2014 Axios version 0.15.3 is not affected by CVE-2026-44487. The vulnerability requires dynamic proxy re-resolution on redirect (a feature introduced in axios 0.27.2), which is absent from version 0.15.3. In this version, all redirects unconditionally reuse the same proxy configuration as the initial request, preventing the proxy credential leak scenario described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f13366c6-0ee1-5769-9b82-6b3ab27c037c",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a236f5a7-a0e3-5e80-acd9-7990a4b47c45",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 0.15.3-tuxcare.4 of axios. not_affected \u2014 Target version 0.15.3-tuxcare.3 is NOT AFFECTED by CVE-2026-44492. The vulnerability requires the NO_PROXY environment variable mechanism to exist, which was not introduced until version 0.19.1 (commit 38de252, August 2018). The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31d604ca-3682-55bc-a78c-c37edae278bc",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8447c87-b8ee-566c-8c40-d196bfe702b7",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4168ba38-4945-526c-bcfb-97f28316832d",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.15.3-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.15.3-tuxcare.4"
    }
  ]
}