{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:361bfe36-86ab-553f-9fe6-8b3525747d9e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "hono",
      "purl": "pkg:npm/hono@3.12.12-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/hono@3.12.12-tuxcare.1",
      "version": "3.12.12-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-32869",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:582a0de7-eb20-56f2-a69f-8c5a4bf313b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-32869 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2024-43787",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a6b64f03-c15a-5111-92db-d5d31707a743",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-43787 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2024-48913",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b21c597e-999e-5357-850d-f5fd56931f65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-48913 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-59139",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2eed8b4c-ad7f-5c96-98ef-79d112a4060d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-59139 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 Hono version 3.12.12 is not affected by CVE-2025-59139. The vulnerable component (bodyLimit middleware) does not exist in this version. The middleware was introduced later in version 4.0.6 (commit 466bf491, March 2024), making it impossible for the header prioritization vulnerability to manifest in version 3.12.12.",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2025-62610",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc78254b-51a2-56e6-91d9-78df032cf72c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62610 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22817",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf2b9a36-1920-5020-961f-6de54290a869",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22817 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22818",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3da41d5a-c40c-5246-9eb7-98e83e6b0a7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22818 affects version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-24398",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f94641c7-727c-5311-be4f-4d59a5cb7b21",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-24398 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target repository (Hono version 3.12.12) is not affected by CVE-2026-24398. The vulnerable IP Restriction Middleware feature and its associated IPv4 validation code in `src/utils/ipaddr.ts` do not exist in this version. The feature was introduced in version 4.x (commit 71cdcf40) and subsequently patched in version 4.11.7 (commit edbf6eea). Version 3.12.12 predates the feature introduction e...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-24472",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5dedc1cc-5c09-5bcc-aaa0-a0d7a8f68dfb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24472 affects version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-24473",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0b51262c-35e9-5751-81be-82da606a0c61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24473 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-24771",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc964374-0c5b-5004-8950-29a97c73afbc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24771 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-29045",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7972bc51-ad01-5ca4-af1a-d2de278a52ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29045 affects version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-29085",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6803939f-bbb1-55fd-b6aa-c88a41bce7bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29085 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-29086",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ebaa47ca-f1b5-519d-babc-ebd79da21338",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29086 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-39407",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:76e9bcd7-6c61-5f0c-aaaf-ffa5b3f67736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39407 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-39408",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b5e99ad-0309-528d-9a24-d4ed1ae3ea63",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39408 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 Version 3.12.12 is not affected by CVE-2026-39408. The SSG (Static Site Generation) feature, which contains the vulnerable toSSG() function with the path traversal issue, does not exist in this version. The SSG helper was introduced in commit 04b686ca after v3.12.12 was released, on a separate development branch (v4.x) that was never backported to the 3.x series. The vulnerability's attack surf...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-39409",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b867662-4d42-5fed-8744-906c9472eee5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39409 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target repository (Hono v3.12.12) does not contain the vulnerable ipRestriction() middleware. The CVE-2026-39409 vulnerability affects Hono's IP restriction middleware which fails to canonicalize IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) before matching against IPv4 allow/deny rules. However, the ipRestriction middleware was introduced in version 4.x (commit 71cdcf40) and does not exist i...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-39410",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:83d09bf3-77ac-560a-8ddd-ad7230ddafff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39410 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-44455",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67643030-dd19-5572-b1c8-e27949f73481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44455 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-44456",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:67340467-8674-5f6c-8d25-10007384ebf0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44456 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target version 3.12.12 is NOT AFFECTED by CVE-2026-44456. The vulnerability concerns the bodyLimit() middleware's failure to enforce maxSize for chunked requests. However, the bodyLimit middleware component does not exist in version 3.12.12 - it was introduced later in v4.1.0 (138 commits after v3.12.12). Without this middleware component, the vulnerability pattern described in the CVE cann...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44457",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0d451f9f-3230-55a7-82c9-9a21f3943fc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44457 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-44458",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:46a581da-35e8-5ecc-85fd-864dde120c05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44458 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44459",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c202921-8eba-5aa2-a21f-eecab4c5e7b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44459 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-47673",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b71951c-f97e-549f-90d7-15aa0238db44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47673 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-47674",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49f153f6-fcbe-5437-9635-4e0c8bdbe178",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47674 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target repository (Hono v3.12.12) does not contain the vulnerable ip-restriction middleware. The middleware was introduced in version 4.5.0, significantly after the target version. Exhaustive searches confirm that neither the middleware nor its associated ipaddr utilities (convertIPv6ToBinary, convertIPv4ToBinary, distinctRemoteAddr) exist in the target codebase. The vulnerability cannot ma...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-47675",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:35208903-4314-500a-987c-0a945ff590c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47675 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-47676",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80fa06d5-02dd-5086-9496-767d2613472c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47676 affects version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-54286",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:edfb092c-08b0-55ee-80d0-6eb93ab97b6b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54286 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-54287",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:117e23ac-94ad-54e3-a26c-ed4ad565a1fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54287 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-54288",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85eaa55d-9751-5ef8-b584-dbf3d43e5801",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54288 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 Version 3.12.12 is not affected by CVE-2026-54288. While the Lambda adapters contain the underlying data flaw (they trust the client's Content-Length header without recalculating it based on actual body size), the vulnerability cannot be exploited because the Body Limit Middleware - the component whose security checks would be bypassed - does not exist in this version. The Body Limit Middleware...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-54289",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:10240173-2162-555a-b7f2-4f7543152db5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54289 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-54290",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80235c05-b6da-56f0-96d1-9cf731e11c9b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54290 affects version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-56761",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b59362e-5fec-59f0-8376-f86ce0d0fc5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56761 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-56762",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:976c9510-61c3-568f-a3a6-4def0dde35fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56762 affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-69207",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b19973c-1804-5ee3-a574-e55c4a34471a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69207 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-71850",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48355f1e-3684-5a87-9111-af1b7799f5ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-71850 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-84363",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ea681b2-cca1-5dd7-a138-c7a9a1d120d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-84363 is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "CVE-2026-84364",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:06f28557-71be-5940-9828-f15023921ada",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-84364 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target version 3.12.12 is not affected by CVE-2026-84364. The vulnerability concerns unbounded memory allocation during dot-notation parsing of form field names, but this feature does not exist in version 3.12.12. Dot-notation parsing was introduced in v4.4.0 (commit 568f8725) and the vulnerability was fixed in v4.13.5. The target's body.ts stores dotted keys literally (e.g., \"a.b.c\" as a s...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-84365",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:42fae7a6-9c63-50d4-9371-1852d62420cc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-84365 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target version 3.12.12 does not contain the SSG (Static Site Generation) feature or any of its vulnerable code. The SSG helper was introduced in Hono v4.0.0, eleven commits after the target version. Since the toSSG() function, ssgParams, and all path normalization utilities (joinPaths, ensureWithinOutDir) do not exist in this version, the vulnerability cannot manifest. The target version pr...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-26pp-8wgv-hjvm",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ed4451cc-a94e-502f-89af-3ceef6c54db6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-26pp-8wgv-hjvm affects version 3.12.12-tuxcare.1 of hono, and is fixed in 3.12.12-tuxcare.2."
      }
    },
    {
      "id": "GHSA-55cm-p4ww-685g",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f3d0367e-9097-5dd9-84e1-6be34a52defe",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-55cm-p4ww-685g is a false positive for hono 3.12.12-tuxcare.1."
      }
    },
    {
      "id": "GHSA-gq3j-xvxp-8hrf",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e633731d-d844-5ba8-9d5d-fc44d714aa70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gq3j-xvxp-8hrf is fixed in version 3.12.12-tuxcare.1 of hono."
      }
    },
    {
      "id": "GHSA-q7jf-gf43-6x6p",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a81d1ed9-18dd-586e-918b-391c0c25dce3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-q7jf-gf43-6x6p does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 Target version 3.12.12 is NOT AFFECTED. The vulnerable code pattern (reading the Vary header from HTTP requests and reflecting it into responses) does not exist in this version. This vulnerability was introduced in v4.4.5 (June 2024) via commit 1a32ef4d and fixed in v4.10.3 (October 2025) via commit d9b8b4b7. Version 3.12.12, released in February 2024, predates the introduction of the vulnerabi...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "GHSA-v8w9-8mx6-g223",
      "affects": [
        {
          "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:056eb65c-e20c-574f-b2d3-57b7e9485202",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-v8w9-8mx6-g223 does not affect version 3.12.12-tuxcare.1 of hono. not_affected \u2014 The target repository (Hono v3.12.12) is not affected by GHSA-v8w9-8mx6-g223. The vulnerability requires the `dot: true` option in `parseBody()` which enables dot notation parsing to create nested objects. This feature was introduced in Hono v4.4.0 (commit 568f8725). The target version v3.12.12 predates this feature and only performs literal string key assignment (`form[key] = value`), making i...",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/hono@3.12.12-tuxcare.1"
    }
  ]
}