{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:79116ace-cf94-505f-a207-c9a1924fa533",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/create-vite@4.5.5-tuxcare.9",
      "type": "library",
      "name": "create-vite",
      "version": "4.5.5-tuxcare.9",
      "purl": "pkg:npm/create-vite@4.5.5-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9b73a7f4-a290-5420-8588-b1037997b24c",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-23331 does not affect version 4.5.5-tuxcare.9 of create-vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-23331. The fix (adding 'nocase: true' to picomatch options) has been applied and is present in the current codebase."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7e42f8e-7232-5ec6-bd75-b83e7a6bfe45",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-31207 does not affect version 4.5.5-tuxcare.9 of create-vite. not_affected - CVE-2024-31207 (server.fs.deny bypass for patterns containing directories) was fixed upstream in vite 5.2.6 / 5.1.7 / 5.0.13 / 4.5.3 / 3.2.10 / 2.9.18. This project version is vite 4.5.5, i.e. above the 4.5.3 fix in the same 4.5.x line, so the fix is already present and no patch is needed. The previous patch_application_error state came from the automation's pre-validation reporting 'Patches already applied'."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc485db7-9cd4-53ba-b01e-a169e13da5ea",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-45811 does not affect version 4.5.5-tuxcare.9 of create-vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02880fac-31bc-5e02-8821-a2acd65d5d70",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f05386c-3a13-5994-beed-d73cae80f84c",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:868d263d-e2f3-545b-bda4-1ebee1f7478e",
      "id": "CVE-2025-30208",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c57a041-07d9-54ae-9b4a-e728d55ecdde",
      "id": "CVE-2025-31125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9ff3b80-4a17-589e-824e-cc96df42d385",
      "id": "CVE-2025-31486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c18b345-b101-5662-9623-6cf7398060e0",
      "id": "CVE-2025-32395",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b31968ed-43d5-5b83-932b-c913e05af441",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:697a586a-1d4c-559e-b37a-8acb9b23f447",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58751 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a3b5934-af3f-583d-a16e-14e6d3266f0c",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d8f85e4-1931-54f0-a58f-bf930e6211ae",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e80f00-c4aa-5882-ae61-7b98bb2b8680",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 4.5.5-tuxcare.9 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114e9f9a-010f-509d-9bcb-e5e4925dc427",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39364 does not affect version 4.5.5-tuxcare.9 of create-vite. vite 4.5.5 is outside the affected version range for CVE-2026-39364 per the GitHub Security Advisory and NIST/NVD."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79a2c275-f031-506d-8df0-53b48f409257",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39365 does not affect version 4.5.5-tuxcare.9 of create-vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41f79d58-7793-57c7-8bf7-a454fc039e12",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53571 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3c7666d-ac53-5c0e-a0c3-00aaedc8dc02",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53632 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75b9ff7-dd8f-534b-a0a8-0d07702e8305",
      "id": "GHSA-4w7w-66w2-5vf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4w7w-66w2-5vf9 is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1f4e377-85cf-5f58-8f67-765a797dd6a2",
      "id": "GHSA-v2wj-q39q-566r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2wj-q39q-566r is fixed in version 4.5.5-tuxcare.9 of create-vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/create-vite@4.5.5-tuxcare.9"
    }
  ]
}