{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b3a1df28-db31-510e-a2c6-60316f1f82b2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/lodash@2.4.2-tuxcare.1",
      "type": "library",
      "name": "lodash",
      "version": "2.4.2-tuxcare.1",
      "purl": "pkg:npm/lodash@2.4.2-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:216a75fb-0509-5847-b26e-7982ad3ebbd6",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-16487 is fixed in version 2.4.2-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af05107a-3dd8-521d-9277-987ec49b71f6",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3721 is fixed in version 2.4.2-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d1b4542-29d0-520b-bec2-c0a8b5a8464b",
      "id": "CVE-2019-1010266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-1010266 does not affect version 2.4.2-tuxcare.1 of lodash. not_affected \u2014 CVE-2019-1010266 does not affect lodash version 2.4.2. The vulnerable functions (words, trim, trimEnd, toNumber) and their associated ReDoS-vulnerable regex patterns (reHasUnicodeWord with {2,}, reTrim with ^\\s+|\\s+$) do not exist in this version. These functions appear to have been introduced in versions after 2.4.2. The vulnerability was introduced with those functions and fixed in version 4...."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:145a9752-d193-5deb-b8d3-a1970edbd599",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10744 is fixed in version 2.4.2-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a6f4c3c-6d9e-5bb9-bb4e-f8e76d6e7f8e",
      "id": "CVE-2020-28500",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-28500 does not affect version 2.4.2-tuxcare.1 of lodash. not_affected \u2014 Lodash version 2.4.2 does not contain the vulnerable functions (toNumber, trim, trimEnd) mentioned in CVE-2020-28500. These functions were added in later versions of lodash (likely 3.x or 4.x). The CVE's claim that 'all versions prior to 4.17.21' are vulnerable is factually incorrect for version 2.4.2."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b70d2b1a-e8ae-5266-ad74-aaa1a94a877c",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-8203 does not affect version 2.4.2-tuxcare.1 of lodash. Lodash version 2.4.2 is not affected by CVE-2020-8203. The vulnerability requires deep property path manipulation functions (set, setWith, update, updateWith, zipObjectDeep) that were introduced in later lodash versions and do not exist in 2.4.2. The functions that do exist in this version (merge, pick, assign, zipObject) either have prototype pollution protections or operate only on shallow property assignments without path traversal. Runtime testing with multiple attack vectors confirms no prototype pollution occurs. The architectural difference between lodash 2.4.2 and 4.17.x means the specific attack chain described in CVE-2020-8203 is not reachable."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce16926-16f1-5421-adc3-de09b517d90d",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23337 is fixed in version 2.4.2-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a6c846-a757-5646-9705-e8b43d65cf0a",
      "id": "CVE-2021-41720",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41720 is a false positive for lodash 2.4.2-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef261db2-c2c6-5d76-b161-4d7cf232532e",
      "id": "CVE-2025-13465",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-13465 does not affect version 2.4.2-tuxcare.1 of lodash. not_affected \u2014 Lodash version 2.4.2 is not affected by CVE-2025-13465. The vulnerability exists in Lodash versions 4.0.0 through 4.17.22 and requires path-based property manipulation functions (_.unset, baseUnset) that were introduced in version 4.x. Version 2.4.2 predates these features and uses a fundamentally different architecture for property operations."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c339afd-03bf-533a-bcb8-2c70976f6226",
      "id": "CVE-2026-16221",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-16221 is fixed in version 2.4.2-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06117236-e631-55ba-8938-9aa005586d9b",
      "id": "CVE-2026-2950",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2950 does not affect version 2.4.2-tuxcare.1 of lodash. not_affected \u2014 Lodash version 2.4.2 is not affected by CVE-2026-2950. The vulnerability requires the _.unset() function and baseUnset() helper for path-based property deletion, neither of which exist in version 2.4.2. The _.omit() function in this version uses a fundamentally different copy-based architecture that creates new objects rather than deleting properties, making the prototype pollution attack vecto..."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a602ecff-9d1c-538f-922f-245675267922",
      "id": "CVE-2026-4800",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4800 affects version 2.4.2-tuxcare.1 of lodash."
      },
      "affects": [
        {
          "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/lodash@2.4.2-tuxcare.1"
    }
  ]
}