{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:34d5166d-2273-56d3-be8c-f5709ebfb23a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@0.21.1-tuxcare.3",
      "type": "library",
      "name": "axios",
      "version": "0.21.1-tuxcare.3",
      "purl": "pkg:npm/axios@0.21.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9de49345-7cc9-5f86-804f-e3d788c814f3",
      "id": "CVE-2021-3749",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ad21541-a428-57c3-9f44-2c1d53edcd26",
      "id": "CVE-2023-45857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9da2992-b133-5838-9d15-6a1907c54a98",
      "id": "CVE-2024-39338",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.21.1-tuxcare.3 of axios. already_fixed \u2014 The target axios 0.21.1-tuxcare.1 already contains equivalent defense logic against CVE-2024-39338 (protocol-relative URL SSRF) through the 'allowAbsoluteUrls' parameter added in CVE-2025-27152 backport (commit bc6d5a0b). When set to false, this parameter forces baseURL concatenation for protocol-relative URLs, preventing SSRF. The defense code exists in the codebase and is reachable on all exe..."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78ecab29-6673-5a81-b37f-2ee99596c781",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a26f8934-bd97-5fc2-bd73-97bfe4a33e10",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad311193-034a-5edc-82dd-9d51e19c13d8",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24850433-76ed-55b5-976e-c32003753bd5",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4691f70-00a7-5055-8d24-dcf6f6c3432d",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bf37b79-4f07-5d75-ad58-c614b597db50",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cece163-6602-55b0-bb12-511b728a0a58",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8abe500b-4dc8-54ce-8db6-327202c92396",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f19b5c5e-7e3e-5a1f-a646-87ca7051e3aa",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daba4f80-3a05-5ce5-8773-333af5a19b9e",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d89eab8-bfde-5cd0-bc4f-381844bfdba7",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71098dd8-456c-503f-9bc4-314eadd6545f",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ea7be59-4ea6-5ac0-a800-e232467ef8af",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c87b48-173a-5192-bcbe-1d0a74467c1c",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42043 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd43563-ce91-5d4e-849e-eb9d81680644",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a33d6f9-3550-5281-a316-5384de28407f",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7f6b7c-204a-5416-84fb-1de71ba3f597",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78c6a041-6520-5aa4-81ac-acadb4682338",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84685334-bfe3-567b-83b6-05856f1aff91",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ec4b631-4bc4-5c22-a269-d4358cb5b0f1",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224d5bd8-fc03-5b07-8c80-445c6a8392e5",
      "id": "CVE-2026-67316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67316 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa9c87b-a5cb-5967-8e7f-49bbadcd0136",
      "id": "CVE-2026-67319",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67319 is fixed in version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e9ddbaa-8875-5f02-990a-f4a372b7508c",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cdd19e7-2036-5dd2-8578-dac0d274ea95",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.21.1-tuxcare.3 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.21.1-tuxcare.3"
    }
  ]
}