{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:665717a0-49fa-5e4b-b7c6-14975dffbffe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/vite@4.5.5-tuxcare.9",
      "type": "library",
      "name": "vite",
      "version": "4.5.5-tuxcare.9",
      "purl": "pkg:npm/vite@4.5.5-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:952c731a-44a6-5e42-bcc1-9ac5d2a1f234",
      "id": "CVE-2024-23331",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-23331 does not affect version 4.5.5-tuxcare.9 of vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-23331. The fix (adding 'nocase: true' to picomatch options) has been applied and is present in the current codebase."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4cd8902-dda3-5ff4-bed5-4d79dbc6f73e",
      "id": "CVE-2024-31207",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-31207 does not affect version 4.5.5-tuxcare.9 of vite. not_affected - CVE-2024-31207 (server.fs.deny bypass for patterns containing directories) was fixed upstream in vite 5.2.6 / 5.1.7 / 5.0.13 / 4.5.3 / 3.2.10 / 2.9.18. This project version is vite 4.5.5, i.e. above the 4.5.3 fix in the same 4.5.x line, so the fix is already present and no patch is needed. The previous patch_application_error state came from the automation's pre-validation reporting 'Patches already applied'."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a14fd6f5-f861-517b-b987-4f66aabf6932",
      "id": "CVE-2024-45811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-45811 does not affect version 4.5.5-tuxcare.9 of vite. Version 4.5.5 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-45811. The fix is present in a semantically equivalent form, using `checkServingAccess` with `deniedServingAccessForTransform` instead of the vendor's `ensureServingAccess`, but providing identical protection against the ?import&raw bypass vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67a51c75-7402-5c17-9827-98ec61d3c039",
      "id": "CVE-2024-52011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52011 affects version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db6c0e8b-1adc-5977-a053-d33f7ccb2109",
      "id": "CVE-2025-24010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24010 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e80e16-7284-5cca-bff0-f50448c321c8",
      "id": "CVE-2025-30208",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-30208 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5d2b30-1160-5bc5-9420-8718f1ca8721",
      "id": "CVE-2025-31125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31125 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efff4613-7f23-5812-97fe-086b3ace3187",
      "id": "CVE-2025-31486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31486 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc49e82-e94e-596e-a8de-13d3c457277a",
      "id": "CVE-2025-32395",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32395 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a56eec-0877-5878-98d7-ca76876d6c7b",
      "id": "CVE-2025-46565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46565 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3eeba9f-fa1d-5eb4-a7cb-cddcc5f3a325",
      "id": "CVE-2025-58751",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58751 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae669f1f-6cd8-5c42-8de7-9b586e7c0191",
      "id": "CVE-2025-58752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58752 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2715c228-82e2-5948-91bc-f4503b5cb4b4",
      "id": "CVE-2025-62522",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62522 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41bdb26a-71d4-5127-9723-cd4f7eb5dce4",
      "id": "CVE-2026-39363",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39363 does not affect version 4.5.5-tuxcare.9 of vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39363 does not affect Vite 4.5.5. The vulnerability requires fetchModule method and vite:invoke WebSocket event, which were introduced in later versions (5.x/6.x). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39c6afd-ff1f-5312-9955-9baf6d450c67",
      "id": "CVE-2026-39364",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39364 does not affect version 4.5.5-tuxcare.9 of vite. vite 4.5.5 is outside the affected version range for CVE-2026-39364 per the GitHub Security Advisory and NIST/NVD."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db864aec-a637-5cc2-af35-33b99ef6b4d6",
      "id": "CVE-2026-39365",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39365 does not affect version 4.5.5-tuxcare.9 of vite. Version 4.5.5 is not vulnerable. Summary: CVE-2026-39365 path traversal vulnerability was present in the original Vite v4.5.5 but has been patched in version 4.5.5-tuxcare.7. The fix (commit 91f0a4f50, backported on 2026-04-20) adds validation to ensure .map file requests for optimized dependencies cannot traverse outside the optimized deps directory via '../' segments in the URL. The target repository currently includes this security patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f4f16b-a3a1-5857-a665-e8170ee9b3f0",
      "id": "CVE-2026-53571",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53571 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b784c537-2de0-5533-9c09-23ef7df8a6ce",
      "id": "CVE-2026-53632",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53632 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c61b2385-5641-5e14-a6db-e9d60fc9a154",
      "id": "GHSA-4w7w-66w2-5vf9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4w7w-66w2-5vf9 is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe79e0d8-a759-55fa-bc0e-2534e61bee73",
      "id": "GHSA-v2wj-q39q-566r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v2wj-q39q-566r is fixed in version 4.5.5-tuxcare.9 of vite."
      },
      "affects": [
        {
          "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/vite@4.5.5-tuxcare.9"
    }
  ]
}