{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dfcf6d64-dd9b-505f-bbae-f7650f7aeff2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.27.2-tuxcare.2",
      "type": "library",
      "name": "axios",
      "version": "0.27.2-tuxcare.2",
      "purl": "pkg:npm/axios@0.27.2-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e23f8dc8-4c63-5007-9556-33219491fad1",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a481ac-8a41-5a4f-a363-9df6261efd4d",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.27.2-tuxcare.2 of axios. Version 0.27.2 is not vulnerable. Summary: The target repository (axios 0.27.2-tuxcare.1) is NOT vulnerable to CVE-2024-39338. It uses the legacy url.parse() API instead of the vulnerable new URL() constructor with hardcoded 'http://localhost' base. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86ad0ec6-f5f1-52b7-a475-f8d9d7c2085b",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:826d0020-2fe0-519f-957c-b37d62f1af72",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4802038-34ad-516d-a375-f6e758e89c55",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03cb1abe-4a58-5f6d-accb-af3df89f8cdd",
      "id": "CVE-2026-39865",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39865 does not affect version 0.27.2-tuxcare.2 of axios. not_affected \u2014 Target axios version 0.27.2-tuxcare.4 is not affected by CVE-2026-39865. The vulnerability requires HTTP/2 session management code (Http2Sessions class with getSession method) that does not exist in this version. HTTP/2 support was added to axios in version 1.x (commit d676df77, October 2025), while this target is based on axios 0.27.2 from April 2022 and only supports HTTP/1.x. The vulnerable ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2419a7c9-ba50-53f9-be7b-cf81eaf06008",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fcf478b-0f34-5151-9cbf-d9b8da515df7",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e175f99-c207-55ce-b848-046abc577fd7",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b101a8ad-ec80-5214-8f2a-63657f98adeb",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfde85c5-243f-551d-9fc5-d37b7553ce03",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:017958ec-2e6e-5967-a3aa-49929d20a38b",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6b63466-56a5-5e51-91a5-d2cef054622d",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42039 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea10e27-b456-5097-9862-b0270871dc0f",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42040 does not affect version 0.27.2-tuxcare.2 of axios. not_affected \u2014 The target version (axios 0.27.2-tuxcare.4) is NOT AFFECTED by CVE-2026-42040. The vulnerable component (lib/helpers/AxiosURLSearchParams.js) does not exist in this version. Historical analysis shows this file was introduced in commit 934f390c, which is 65 commits AFTER the v0.27.2 release and first appeared in v0.28.0. In v0.27.2, URL parameter encoding is handled by lib/helpers/buildURL.js:en..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6833e093-d580-58f9-b5f3-f09372576aac",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1abad096-5e40-560b-8301-aad8f5fa0753",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 0.27.2-tuxcare.2 of axios. not_affected \u2014 Target version 0.27.2-tuxcare.4 is NOT affected by CVE-2026-42042. The vulnerability requires the `withXSRFToken` configuration feature, which was never introduced to the 0.27.2 lineage. The XSRF token logic in this version always enforces same-origin checking via `isURLSameOrigin(fullPath)` with no bypass conditions. Prototype pollution of `Object.prototype.withXSRFToken` has no effect because..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4718572-1335-52bd-bbc0-99e6dac954de",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ae04bc1-f3e4-51c1-a771-b4d031e7cbaf",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c664532c-dfe6-535f-93cc-e79dc69dcd01",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a5267a-fa22-5af3-af82-e99b658d5899",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9234842-d16c-5904-a464-7b8910b8b3b9",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f70a89aa-0bb0-5238-b43b-ae91d5dcba1e",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:734084ce-1829-53a8-9f30-43f76863a0b2",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3102dd78-1dc3-5df9-9483-12f9ba2395a9",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7925e8a-2b5e-5575-afb9-cbdf54cf2f07",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.27.2-tuxcare.2 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.27.2-tuxcare.2"
    }
  ]
}