{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:10209622-7fe4-556d-af33-7b8fb52e3266",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/devalue@4.3.0-tuxcare.1",
      "type": "library",
      "name": "devalue",
      "version": "4.3.0-tuxcare.1",
      "purl": "pkg:npm/devalue@4.3.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a997ee22-6d37-54b6-bfa7-9008c983c040",
      "id": "CVE-2022-21670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-21670 is fixed in version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:552ca2d2-0540-5b22-afdf-9a78b5123dfd",
      "id": "CVE-2025-57820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57820 affects version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c18c6a-8d35-5004-8123-f20105389899",
      "id": "CVE-2026-22774",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22774 does not affect version 4.3.0-tuxcare.1 of devalue. Target version 4.3.0 is not affected by CVE-2026-22774. The vulnerability exists in TypedArray hydration code that validates ArrayBuffer inputs, but TypedArray support was not introduced until version 5.1.0. Version 4.3.0 predates this feature entirely. When typed array serialized data is provided to this version, the parser throws \"Unknown type Int8Array\" error rather than attempting hydration, preventing the DoS condition described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecae559c-af94-53ac-9d82-d3f72b1536ea",
      "id": "CVE-2026-30226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-30226 affects version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981ccd05-5dc6-547f-873f-a8425a665f0a",
      "id": "CVE-2026-42570",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42570 affects version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42316dcc-0938-5699-b628-d0019149f304",
      "id": "GHSA-33hq-fvwr-56pm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-33hq-fvwr-56pm affects version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:521f6f8a-b1ac-5c6b-a245-7cda1e3386d0",
      "id": "GHSA-8qm3-746x-r74r",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8qm3-746x-r74r affects version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:400e2240-32a5-57fd-a41f-f9c119db7ba9",
      "id": "GHSA-mwv9-gp5h-frr4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mwv9-gp5h-frr4 affects version 4.3.0-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/devalue@4.3.0-tuxcare.1"
    }
  ]
}