{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2cb4b80d-6686-568c-b6a0-b252a8dd769a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/handlebars@1.0.12-tuxcare.2",
      "type": "library",
      "name": "handlebars",
      "version": "1.0.12-tuxcare.2",
      "purl": "pkg:npm/handlebars@1.0.12-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:50a5a9c4-3bc3-5fc1-9add-537ea857b7a9",
      "id": "CVE-2015-8861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8861 is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d21375-24a6-51c4-a701-7efcb0bb007a",
      "id": "CVE-2019-19919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-19919 is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e23ce68-0f66-5c79-9ebb-2f5497cfbc69",
      "id": "CVE-2019-20920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20920 is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c7f51a-8c89-588a-82da-9bf7e373e3f2",
      "id": "CVE-2021-23369",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23369 is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64152444-5a2e-5c1f-bc0c-6af13ca624d2",
      "id": "CVE-2021-23383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23383 is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9348d3-aa8c-5c75-9820-0c250bb91d0d",
      "id": "CVE-2026-33937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33937 affects version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24c6e3ec-50eb-5808-b5c4-ebe70b55a482",
      "id": "CVE-2026-33938",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33938 does not affect version 1.0.12-tuxcare.2 of handlebars. Version 1.0.12 does not support the @partial-block feature required for CVE-2026-33938 exploitation. The vulnerability requires: (1) a helper mutating @partial-block in the data frame with a crafted AST, (2) invoking {{> @partial-block}} to trigger dynamic compilation. Git history shows @partial-block was introduced in commit 94c840b AFTER version 1.0.12 was released (commit 2a073e0). The parser rejects @ tokens in partial names with error \"Expecting 'STRING', 'INTEGER', 'ID', got 'DATA'\". No code in lib/ reads options.data['partial-block']. The attack chain cannot execute."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca2f2b3-9ea3-54a5-a84a-9c81b69120c9",
      "id": "CVE-2026-33939",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33939 does not affect version 1.0.12-tuxcare.2 of handlebars. Handlebars version 1.0.12 does not support decorator syntax ({{*decoratorName}}). Decorator support was introduced in Handlebars 4.x. The vulnerable code path\u2014decorator compilation in lib/handlebars/compiler/javascript-compiler.js\u2014does not exist in this version. The parser has no OPEN_DECORATOR token, the AST has no DecoratorNode type, and the compiler contains zero references to decorators. The target cannot receive the malicious INPUT (decorator syntax) identified in the attack vector, satisfying Rule 5 Type A1 (input absent)."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98454bd0-5f76-5e83-ae81-c3f2e75cecec",
      "id": "CVE-2026-33940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33940 affects version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7975de5e-5836-57c2-8269-a22d5f454e1e",
      "id": "CVE-2026-33941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33941 affects version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5cb6dd-b480-5cee-a9bc-ff7753bd25e6",
      "id": "GHSA-2cf5-4w76-r9qv",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-2cf5-4w76-r9qv is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a7e0143-c27e-5403-a757-49e5bf252cff",
      "id": "GHSA-442j-39wm-28r2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-442j-39wm-28r2 does not affect version 1.0.12-tuxcare.2 of handlebars. not_affected \u2014 Version 1.0.12 is not affected by GHSA-442j-39wm-28r2. The vulnerable `container.lookup()` function with the TOCTOU bug doesn't exist in this version. Version 1.0.12 uses a fundamentally different architecture where `lookupProperty` reads a property once and all code paths return that same validated result, eliminating the double-read pattern required to exploit the vulnerability. The {compat: ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81f91b5-de5a-5add-affc-8268d0367291",
      "id": "GHSA-6r5x-hmgg-7h53",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6r5x-hmgg-7h53 is a false positive for handlebars 1.0.12-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a62fe6b4-65b2-5f52-97b8-24d1da68ed11",
      "id": "GHSA-7rx3-28cr-v5wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7rx3-28cr-v5wh affects version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b8118d-5943-5357-bff0-40e51bd9d8bf",
      "id": "GHSA-fmr4-7g9q-7hc7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fmr4-7g9q-7hc7 is a false positive for handlebars 1.0.12-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e600e83-60fb-5301-8425-b83a336c1086",
      "id": "GHSA-g9r4-xpmj-mj65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-g9r4-xpmj-mj65 is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84ae3fcd-5514-5e2d-b875-3744c8c70720",
      "id": "GHSA-q2c6-c6pm-g3gh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q2c6-c6pm-g3gh is fixed in version 1.0.12-tuxcare.2 of handlebars."
      },
      "affects": [
        {
          "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/handlebars@1.0.12-tuxcare.2"
    }
  ]
}