{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7565e1fe-f776-52a3-9add-04a7a34ac230",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1",
      "type": "library",
      "name": "dcodeIO_dcodeIO_protobuf.js",
      "version": "6.10.2-tuxcare.1",
      "purl": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:20eafcd0-9541-5ba0-9207-145130722ebe",
      "id": "CVE-2022-25878",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25878 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd6479d0-1883-5f29-a273-985edb5cd7a1",
      "id": "CVE-2023-36665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36665 is fixed in version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b360f280-794a-50fb-b464-cb1704f7722b",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:967b7720-94be-5a6c-8717-715ddbfdeea6",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44288 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec227747-8a11-5498-8628-87773206d2a4",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44289 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abadf7a7-0b41-5a9f-a0e5-53e8ef87f56a",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js. CVE-2026-44290 fix already exists in commit f87c65fb1bedc7be0ee2504542878b86ee943218"
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ab6426-7469-55c9-bb22-eb85069d41c0",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44291 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eadf693b-c8bd-54b3-9730-b0aaf031e852",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44292 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bc7da14-5316-5e9a-bfb5-2e1a198f29df",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44293 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52776e3-17dc-5625-86fe-0d6574474475",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44294 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e406ef-9300-5770-b8fc-ac64f133318b",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:674611a8-4ee3-5329-8242-a409633736ec",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ecabb3-7af1-547e-8df4-944d7aa1bc0c",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b57438b1-6f30-5da3-8f06-bc70635d20a8",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js. not_affected \u2014 Target version 6.10.2 is not affected by CVE-2026-54270. The vulnerability concerns excessive memory retention from unknown field preservation, a feature introduced in protobufjs 8.2.0. Version 6.10.2 does not implement unknown field preservation; unknown fields are simply skipped during decode without storing them in memory."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38d9645b-63e5-5e77-8053-8a38e18013d6",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js. not_affected \u2014 CVE-2026-59876 specifically affects the optional Text Format extension (ext/textformat.js) which does not exist in protobufjs version 6.10.2. This extension was introduced as a new feature in version 8.x. Without the Text Format extension, the attack vector described in the CVE cannot be exploited."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63db2551-eb72-5f48-8d42-12811b544bf2",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.10.2-tuxcare.1 of dcodeIO_dcodeIO_protobuf.js. not_affected \u2014 Version 6.10.2 is not affected by CVE-2026-59877. The vulnerable code pattern (a while loop advancing through tokens looking for '=' without EOF checking) does not exist in this version. Version 6.10.2 uses a different architecture with skip('=') that properly handles EOF by throwing an error."
      },
      "affects": [
        {
          "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dcodeIO_dcodeIO_protobuf.js@6.10.2-tuxcare.1"
    }
  ]
}