{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1cb28497-79ee-5721-90ed-3ca9affe47bc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/svelte@0.3.0-tuxcare.2",
      "type": "library",
      "name": "svelte",
      "version": "0.3.0-tuxcare.2",
      "purl": "pkg:npm/svelte@0.3.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ea1e46d1-183d-585d-b554-824dcf069345",
      "id": "CVE-2015-8315",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8315 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c17d6c9-2cf5-5ece-ad1d-27ec2f4dc14d",
      "id": "CVE-2016-10539",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10539 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ff25f4f-f8fd-55ff-8a08-5c0a218a52e6",
      "id": "CVE-2016-10540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-10540 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bc3fe8-f759-572d-80b4-3f2f22b78a24",
      "id": "CVE-2017-16119",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16119 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c8ee18-ae35-533f-906a-b4eca45af81c",
      "id": "CVE-2017-20162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-20162 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2259eb4e-d767-5fce-8c52-7a35cb04509a",
      "id": "CVE-2021-29060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-29060 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90d6a190-3824-5972-813f-a7568306f91b",
      "id": "CVE-2022-0144",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-0144 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f77c361b-1f02-5bb3-a655-217a567a102e",
      "id": "CVE-2022-23540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23540 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e04bb28-c8e7-5c26-ad13-5b8fd0c316cd",
      "id": "CVE-2022-25875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25875 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43bdcc22-5176-541b-9cd6-5c2d7a21a071",
      "id": "CVE-2022-3517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-3517 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12bd4822-3e36-5775-9cbd-142dcd367b3f",
      "id": "CVE-2024-45047",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45047 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802a5472-f3d0-5d12-8c55-72eab356bbaf",
      "id": "CVE-2025-15265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15265 does not affect version 0.3.0-tuxcare.2 of svelte. not_affected \u2014 Version 0.3.0 is not affected by CVE-2025-15265. This vulnerability requires Svelte's server-side rendering (SSR) with async hydration capabilities and the `hydratable` function, introduced in Svelte 5.x. Version 0.3.0 (released ~2016-2017) is a client-side-only compiler with no SSR, no hydration functionality, and no `hydratable` function. The vulnerable code path (`packages/svelte/src/interna..."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6911246f-f5bf-5732-ab76-5c5a89895b72",
      "id": "CVE-2026-27121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27121 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5ab5ff-4e74-570f-bcb7-915cf87c097c",
      "id": "CVE-2026-27122",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27122 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af57040-360c-5957-930a-8cdf043bc7fb",
      "id": "CVE-2026-27125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27125 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd93607c-0b1c-59a3-b51a-2885c106e32b",
      "id": "CVE-2026-27901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27901 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cf5bbfc-9358-53db-a79a-eafa98df236c",
      "id": "CVE-2026-42567",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42567 does not affect version 0.3.0-tuxcare.2 of svelte. not_affected \u2014 Svelte 0.3.0 is not affected by CVE-2026-42567. The target version has a fundamentally different architecture than the modern Svelte 5.x codebase where this ReDoS vulnerability exists. The vulnerable regex pattern `[a-zA-Z0-9-]*[a-zA-Z0-9]` (which causes catastrophic backtracking with overlapping quantifiers) is not present in this version. Instead, the target uses a simpler, ReDoS-safe validat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d7cf364-6218-585e-a173-7c267acccd40",
      "id": "CVE-2026-42573",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42573 does not affect version 0.3.0-tuxcare.2 of svelte. not_affected \u2014 Svelte 0.3.0 is not affected by CVE-2026-42573. The patch addresses a string replacement XSS vulnerability in the `hydratable()` function used for server-side rendering (SSR) in modern Svelte (v4/v5). Svelte 0.3.0 has no built-in SSR infrastructure, no `hydratable()` function, and no promise serialization mechanism. The vulnerable code path is entirely absent from this version. While the compil..."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc2eb3b1-da1c-55a5-b9cb-e2a415ed60c6",
      "id": "CVE-2026-42599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42599 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc5ed69a-d27d-5ca2-9c76-fd89a63d3d5e",
      "id": "GHSA-64g7-mvw6-v9qj",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-64g7-mvw6-v9qj is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b0b4cee-737f-5ef3-ac72-a80204fdf4f0",
      "id": "GHSA-f3cj-j4f6-wq85",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-f3cj-j4f6-wq85 does not affect version 0.3.0-tuxcare.2 of svelte. not_affected \u2014 The target repository (Svelte 0.3.0-tuxcare.2) is not affected by GHSA-f3cj-j4f6-wq85. The vulnerability concerns the `hydratable` feature which handles promise serialization in server-side rendering. This feature was introduced in Svelte 5.43.15 (commit c2a110cd8), while the target version is 0.3.0, predating the feature by many major versions. Exhaustive search confirms zero occurrences of \"h..."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8a823ba-ebb3-5aa8-bc5e-f03d3c4d7d00",
      "id": "GHSA-xc7v-wxcw-j472",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xc7v-wxcw-j472 is fixed in version 0.3.0-tuxcare.2 of svelte."
      },
      "affects": [
        {
          "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/svelte@0.3.0-tuxcare.2"
    }
  ]
}