{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:67212f9b-f5d6-5e3d-b7e2-a6d4066a1a26",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-astro@0.26.1-tuxcare.2",
      "type": "library",
      "name": "create-astro",
      "version": "0.26.1-tuxcare.2",
      "purl": "pkg:npm/create-astro@0.26.1-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bb1de9d8-236d-5912-be3a-e7dea64a2c10",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbdc192f-5d1c-544e-9dbe-9ed67a78d954",
      "id": "CVE-2024-56140",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56140 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:900e53d1-e9f0-56c8-a81a-6f102365853e",
      "id": "CVE-2024-56159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56159 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b08683bb-810d-55d9-899b-ac35cc129338",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0824d3a-8223-5cad-9481-608ebdcf263f",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55303 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:717f194b-ad51-507a-b1b8-62ec0ac4feb5",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5910e171-b7a7-597e-b8f4-4b23f72d4ca1",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5af6a8a-f265-57dc-babf-70c63c74663c",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fea09d2-82b0-5464-8779-f2628eb56f3c",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31b9dbd8-7e2e-5665-bd84-c34c70f5c093",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd7b71e1-ccc5-56a4-94bf-673c76a7f9df",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cd4f7a8-8cd4-5195-913d-01473af83c61",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:048a3330-1be9-5f0d-9cf3-4fadbd4101c7",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a4f49f-df38-5864-bba8-6517a4d87b99",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c248aba-81b3-564e-b5de-6b1bcc618921",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b15359-c914-55e4-91e5-5a9f6878d0ca",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5074dad-9ca0-52ec-8457-553289afde69",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b9e5968-0fec-5b02-a65c-2826b9d65b56",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4e6acd2-1cbc-5c9c-860c-2dccc03a4645",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f3f2e8-bd84-53af-b33f-33a5ae64f0f5",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:825eec33-dc7d-542a-8c0d-8b2811e3da12",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50435ffb-2ff8-58f0-821f-4534a550d5fe",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41163fe2-fae4-5b73-b723-206ea7eb288b",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec728df2-0b2e-588c-96da-1bd320dfc136",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c78840-2c6c-5e39-ba75-f8301391ff9d",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42043 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0a00c8b-03c9-5576-94cc-6b73ed0ab025",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2dfbeb4-1743-5ff7-a10a-13e6af590422",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3166a414-3106-5dac-b1a2-a129767bc190",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45028 does not affect version 0.26.1-tuxcare.2 of create-astro. not_affected \u2014 Astro version 0.26.1 does not contain the server islands feature at all. Server islands were introduced to Astro in July 2024 (commit d495df5361), while version 0.26.1 is from 2022. CVE-2026-45028 requires server islands with AES-GCM encryption for props/slots parameters to exist, but this version predates that entire feature. The vulnerable code path (encryption.ts, server-islands/endpoint.ts,..."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7809efb9-cfd4-5758-9a7a-ed180043cc27",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50146 does not affect version 0.26.1-tuxcare.2 of create-astro. not_affected \u2014 Version 0.26.1 uses a fundamentally different slot hydration architecture that predates the vulnerable pattern. The target creates a single template element with a marker attribute `data-astro-template` (no value), while the modern version interpolates slot names into the attribute value. The dangerous operation (slot name interpolation into HTML attributes) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944717a1-036b-50f1-9ce5-0f0a88930778",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54298 is fixed in version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5834aaa3-5668-5016-acc9-3dc8cff2062c",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 0.26.1-tuxcare.2 of create-astro. not_affected \u2014 Target version 0.26.1 does not have the prerendered error page feature that is vulnerable in modern Astro. The RouteData interface lacks the 'prerender' field, and the error handling infrastructure that fetches error pages over HTTP (default-handler.ts) does not exist. When errors occur, this version returns simple inline Response objects without making any HTTP requests."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ff5b28-28eb-5ab0-9218-ac0bba0aec07",
      "id": "CVE-2026-59729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59729 affects version 0.26.1-tuxcare.2 of create-astro."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3439ee4-38a0-5fa5-bcb5-a38b0f77fe70",
      "id": "CVE-2026-73422",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-73422 does not affect version 0.26.1-tuxcare.2 of create-astro. not_affected \u2014 Astro version 0.26.1 is not affected by CVE-2026-73422. The View Transitions feature, which is the attack surface for this vulnerability, does not exist in this version. View Transitions were introduced in Astro versions from 2023 onward (v2.x+), while this target is from April 2022. The vulnerable code path (packages/astro/src/runtime/server/transition.ts) and all related APIs (transition:anim..."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef585de7-f054-5df9-a00e-a07ce082de80",
      "id": "GHSA-4g3v-8h47-v7g6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-4g3v-8h47-v7g6 does not affect version 0.26.1-tuxcare.2 of create-astro. not_affected \u2014 The target repository (Astro v0.26.1-tuxcare.1) is not affected by GHSA-4g3v-8h47-v7g6. The View Transitions feature, which is the source of the vulnerability, does not exist in this version. View Transitions were introduced much later in Astro v2.9+ (commit 6a12fcecb0, circa June 2023), while this target is from the early beta period (2021). The vulnerable code path (packages/astro/src/runtime..."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-astro@0.26.1-tuxcare.2"
    }
  ]
}