{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:854a8417-acdb-5f7a-975c-e1f7f8ef47d7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1",
      "type": "library",
      "name": "fast-xml-parser",
      "version": "4.2.7-tuxcare.1",
      "purl": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9834fd0b-aa1a-55f8-8ebc-9e9008375e04",
      "id": "CVE-2026-25128",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25128 does not affect version 4.2.7-tuxcare.1 of fast-xml-parser. Version 4.2.7-tuxcare.1 is not affected by CVE-2026-25128. The vulnerable numeric entity processing code (num_dec/num_hex handlers calling String.fromCodePoint with unvalidated code points) was introduced in commit 391f24f, which is not present in the 4.2.7 release. The CVE correctly states it affects versions 5.0.9 through 5.3.3; version 4.2.7 predates the introduction of this feature entirely. The target processes only hardcoded HTML entities and does not handle arbitrary numeric character references."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ffd10fc-995d-59a9-b9fa-b4b87067a79d",
      "id": "CVE-2026-25896",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25896 is fixed in version 4.2.7-tuxcare.1 of fast-xml-parser."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7da787bf-c070-5dc7-9327-83480e75b527",
      "id": "CVE-2026-26278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26278 is fixed in version 4.2.7-tuxcare.1 of fast-xml-parser."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b6aa1f-f3ce-528e-93ec-ff806d11f6b6",
      "id": "CVE-2026-27942",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27942 is fixed in version 4.2.7-tuxcare.1 of fast-xml-parser."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d315b8fe-8de5-58f3-b652-93c9430355af",
      "id": "CVE-2026-33036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33036 is fixed in version 4.2.7-tuxcare.1 of fast-xml-parser."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7277db83-4a72-5346-9b69-f96a7d43fbfe",
      "id": "CVE-2026-33349",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33349 is fixed in version 4.2.7-tuxcare.1 of fast-xml-parser."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e048dabc-7d53-5540-8ce2-c33bb00fd527",
      "id": "CVE-2026-41650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41650 is fixed in version 4.2.7-tuxcare.1 of fast-xml-parser."
      },
      "affects": [
        {
          "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/fast-xml-parser@4.2.7-tuxcare.1"
    }
  ]
}