{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:72b64ce1-814f-56f8-9884-68fbf1c67204",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/undici@5.28.5-tuxcare.2",
      "type": "library",
      "name": "undici",
      "version": "5.28.5-tuxcare.2",
      "purl": "pkg:npm/undici@5.28.5-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f83a9ddf-a5d6-51d6-aed3-d57799a04400",
      "id": "AIKIDO-2024-10065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10065 is fixed in version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb182059-c9a8-55ab-96ce-475c77c7d47a",
      "id": "CVE-2024-24750",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-24750 does not affect version 5.28.5-tuxcare.2 of undici. not_affected \u2014 Target version 5.28.5-tuxcare.5 is NOT AFFECTED by CVE-2024-24750. The GitHub Security Advisory (GHSA-9f24-jqhm-jfcw) explicitly states the vulnerable version range is >= 6.0.0 <= 6.6.0. The target version 5.28.5 predates the introduction of the vulnerable code. The vulnerable byteStream with async start callback that eagerly reads all response data was introduced in version 6.0.0 (commit af9aa..."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd6044f4-9e62-5b61-96a7-8ea302b00d86",
      "id": "CVE-2024-24758",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24758 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae75a8f9-7d00-5a01-b2a8-72b6c4451b9e",
      "id": "CVE-2025-47279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-47279 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20105afc-0a6d-546e-8102-31860673f228",
      "id": "CVE-2026-11525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-11525 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d47c5ca-e6c3-573f-8892-558c99f72735",
      "id": "CVE-2026-12151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12151 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16b17c19-1dd4-5209-b29c-f9f03462ac72",
      "id": "CVE-2026-15157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15157 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d5b3776-5878-54be-9b42-9f2d441de6d0",
      "id": "CVE-2026-1525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1525 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b72c2ec-e51f-5ebe-9938-42ec43b0a3c1",
      "id": "CVE-2026-1526",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1526 does not affect version 5.28.5-tuxcare.2 of undici. Target undici version 5.28.5 does not contain the permessage-deflate WebSocket extension implementation. The vulnerable decompression code (PerMessageDeflate class) was introduced in version 6.17.0, well after this version. The extension is explicitly disabled in the handshake code (connection.js line 97), never requested from servers, and no zlib-based decompression code exists in the websocket implementation. Since the vulnerability requires permessage-deflate negotiation and active decompression, and this version cannot perform either, the vulnerability chain cannot exist."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e1ae198-09af-5689-a249-d1c8c6a871f3",
      "id": "CVE-2026-1527",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1527 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b98cd983-b584-599d-b222-c2f69b4a70dd",
      "id": "CVE-2026-16728",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-16728 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e13fc581-d5da-50b5-be88-b6ae37aa3f24",
      "id": "CVE-2026-16729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-16729 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41af94b-57df-5e33-a5b3-80fa01ecdb39",
      "id": "CVE-2026-22036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22036 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887f0d90-eb0b-5381-9dfe-edce7d1fe88d",
      "id": "CVE-2026-2229",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2229 does not affect version 5.28.5-tuxcare.2 of undici. Target version 5.28.5 does not have permessage-deflate support. The vulnerable feature was introduced in undici v6.18.0 (May 2024), multiple major versions after the target. The client never advertises permessage-deflate capability (header append is commented out), the extension negotiation code is disabled with a TODO comment, and the required files (lib/web/websocket/permessage-deflate.js, lib/web/websocket/util.js with isValidClientWindowBits) do not exist. Version 5.28.5 uses the old lib/websocket/ directory structure, predating the lib/web/websocket/ reorganization that accompanied the permessage-deflate feature addition."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67d5d71a-6ed6-519c-8d0c-37769007e35d",
      "id": "CVE-2026-6733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6733 affects version 5.28.5-tuxcare.2 of undici."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f94d20a-166d-5c51-9113-b1c3bf993452",
      "id": "CVE-2026-9679",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-9679 does not affect version 5.28.5-tuxcare.2 of undici. not_affected \u2014 Target repository version 5.28.5-tuxcare.4 is not affected by CVE-2026-9679. The vulnerability was introduced in undici 7.0.0 via commit dac8e73d (PR #3789), which added percent-decoding of cookie values using querystring.unescape(). Git history analysis confirms this commit is NOT an ancestor of the target's current HEAD. The target's cookie parser at lib/cookies/parse.js has never contained p..."
      },
      "affects": [
        {
          "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/undici@5.28.5-tuxcare.2"
    }
  ]
}