{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e53c7ae-68bb-541f-ab62-f39b44997321",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.18.1-tuxcare.5",
      "type": "library",
      "name": "axios",
      "version": "0.18.1-tuxcare.5",
      "purl": "pkg:npm/axios@0.18.1-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98b98c6b-7f4b-502f-a76a-0ec9382e096a",
      "id": "CVE-2020-28168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28168 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6cfc1db-4e04-5a9f-924b-6a733823956a",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1015be-2723-543d-8c03-9a337e162f00",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae3addf-0255-5e1f-8488-d23328bcc223",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39338 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3cc85ad-3268-58a7-aec1-80dbb66633a2",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0451f611-f6b1-53c4-812e-8be2c2824b6b",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4523d1-1a01-59dc-8223-1a3632dcb192",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3073e49-1d02-5f1c-a753-9a48d511d5c7",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad7bfcf-6ef1-5ca5-9391-b70e3a22f0ea",
      "id": "CVE-2026-39865",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39865 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 The target repository (axios 0.18.1-tuxcare.4) is not affected by CVE-2026-39865. This CVE describes an HTTP/2 session cleanup state corruption bug in the Http2Sessions class that was fixed in axios 1.13.2. The target version (0.18.1) predates the introduction of HTTP/2 support in axios, which was added in the 1.x series. The target's lib/adapters/http.js (302 lines) only supports HTTP/1.1 usin..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7e039b-2ee2-5609-ba0a-bc64bdd49af6",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:552a7f30-89c8-5f4a-ba51-9a08a8eaf68b",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5dac46-c0d9-557e-9263-927d75cb2e43",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a0a7fa7-56ef-543c-8143-9655a96510b8",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 0.18.1-tuxcare.5 of axios. Version 0.18.1 (SHA 3256bcea) is NOT affected by CVE-2026-42035. The vulnerable code path does not exist in this version. The attack requires two components: (1) a duck-typed isFormData() function that can be fooled by prototype pollution, and (2) code in lib/adapters/http.js that calls data.getHeaders() and merges the result into request headers. Version 0.18.1 has NEITHER: isFormData() uses instanceof (cannot be spoofed), and http.js has no getHeaders() call. The vulnerable code was introduced AFTER this version in a major ES6 rewrite (302\u2192751 lines), then fixed by commit 854c54e0 authored by CloudLinux engineer Krystyna Tomaszewa. Type A2: INPUT (plain object with polluted properties) is received but no code path reaches GOAL (header injection) because transformRequest JSON-stringifies plain objects before they reach the http adapter."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb9d2148-5bcb-5c85-b05f-80fa423c19cf",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5699d042-33cf-5f45-accb-a01998742056",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:492b3058-b7ae-5da0-89e9-dc4eebc01833",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe04eea-8c76-534c-8316-71bd56bf51cc",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42040 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 Version 0.18.1 is not affected by CVE-2026-42040. The vulnerable component `lib/helpers/AxiosURLSearchParams.js` does not exist in this version\u2014it was introduced in v1.0.0-alpha.1 (commit 934f390c), which postdates 0.18.1. The buildURL.js encode function that exists in 0.18.1 does not contain the reverse-encoding charMap entry ('\"%00\": \"\\x00\"') that causes the vulnerability. Testing confirms th..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba90fa0-3c6e-5806-ac97-e7316d682ab8",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 Axios v0.18.0 is NOT AFFECTED by CVE-2026-42041. The vulnerable code pattern (lib/core/mergeConfig.js with mergeDirectKeys function using the 'in' operator) was introduced in v0.22.0 (September 2021), more than 3 years after v0.18.0 was released (February 2018). Version 0.18.0 uses a completely different architecture: utils.merge() with forEach() that employs Object.prototype.hasOwnProperty che..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c9bfbb0-999c-5e96-8c6b-9dd46de3dff4",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 The target version (axios 0.18.1) is NOT AFFECTED by CVE-2026-42042. The vulnerability concerns the `withXSRFToken` configuration property introduced in later axios versions. Version 0.18.1 predates this feature and uses a completely different XSRF token mechanism based on the `withCredentials` property. Exhaustive searches confirm `withXSRFToken` does not exist anywhere in the codebase, and th..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b1bc36-4eee-5497-922f-d3243f9ddb76",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 0.18.1-tuxcare.5 of axios. Target version 0.18.1 is not affected by CVE-2026-42043. The vulnerability describes an incomplete fix in lib/helpers/shouldBypassProxy.js (lines 1-3) where a hardcoded loopback address set recognizes only 127.0.0.1 instead of the full 127.0.0.0/8 subnet. Version 0.18.1 does not contain this file or any NO_PROXY handling logic. NO_PROXY support was first introduced in axios v0.19.0 (August 2018), and version 0.18.1 predates this feature entirely. The vulnerable code pattern is not present."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f123420c-0679-566c-9d19-35c170bdd6af",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44486 does not affect version 0.18.1-tuxcare.5 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44486 (Proxy-Authorization header leak on redirect). The fix was backported in commit 806a27b (also 3a086d9 in a backport branch), which implements the exact same defense as vendor commit afca61a070728e717203c2bc21e7b589b59b858b."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d7bf18-63d0-5b6f-abea-0d3722679b6a",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44487 does not affect version 0.18.1-tuxcare.5 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44487 (GHSA-j5f8-grm9-p9fc). The exact vendor commit afca61a070728e717203c2bc21e7b589b59b858b was backported in commit 806a27b as part of CVE-2024-28849 remediation on April 28, 2026. The defense mechanism strips stale Proxy-Authorization headers on redirect re-invocations, preventing credential leakage to unintended recipients."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5216d78d-205e-5c9c-9813-ece992edcd60",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b84793d-57ea-5eb0-aafa-891792bad8e3",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 0.18.1-tuxcare.5 of axios. not_affected \u2014 The target repository axios v0.18.1-tuxcare.2 does not implement NO_PROXY functionality at all. The vulnerability CVE-2026-44492 is specific to shouldBypassProxy.js (introduced in v1.15.0) which handles NO_PROXY hostname comparison. Since v0.18.1 predates this feature and has no hostname comparison or bypass logic, the vulnerability pattern cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2adcb5f7-15e4-565f-91c2-3c606fa73793",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78cdf1ae-9c42-5d86-9e1b-33067a6f3301",
      "id": "CVE-2026-67316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67316 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46376156-b7c8-55ae-8a71-766d0f2941bf",
      "id": "CVE-2026-67319",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67319 is fixed in version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5f09caa-3579-55ab-8df2-5174bba0c45f",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acf51e1c-47b6-58d5-b895-fcc481238487",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.18.1-tuxcare.5 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.18.1-tuxcare.5"
    }
  ]
}