{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4093e0e1-9dbf-5fb1-8142-544ba60d799b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/on-headers@1.0.2",
      "type": "library",
      "name": "on-headers",
      "version": "1.0.2",
      "purl": "pkg:npm/on-headers@1.0.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bb2c7c83-3e61-5a58-9d1f-699cd83b849b",
      "id": "CVE-2017-1000048",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2017-1000048 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2017-1000048 affects the 'qs' (query string parser) package, but this repository is 'on-headers' version 1.0.2, a completely different package for HTTP response header manipulation. The affected component (qs.parse and query string parsing functionality) is absent from the entire repository. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c7c99d-c518-5301-9000-385640ad1457",
      "id": "CVE-2018-16487",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2018-16487 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2018-16487 concerns lodash prototype pollution, but this repository is on-headers (a Node.js HTTP header utility). Lodash is not present as the project itself, as vendored code, or as a dependency. This is a wrong-project advisory match."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205cb0fd-d31c-52f8-8712-0c9dee1d7bfb",
      "id": "CVE-2018-3721",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2018-3721 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2018-3721 concerns lodash prototype pollution, but target repository is on-headers (HTTP header listener library). Wrong-project match: lodash code is entirely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f3d469-7acb-55e6-9df4-8c7c6cde5af9",
      "id": "CVE-2019-1010266",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2019-1010266 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2019-1010266 concerns lodash's Date handler ReDoS vulnerability. The target repository is on-headers (version 1.0.2), a completely different Node.js package for HTTP header listener management. Exhaustive containment search found no lodash code, vendored copy, or dependency relationship. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fa50ca8-6b2b-549b-acbd-b38a43459d9d",
      "id": "CVE-2019-10744",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2019-10744 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2019-10744 concerns lodash's defaultsDeep prototype pollution vulnerability, but the target repository is on-headers v1.0.2, a completely different Node.js library for HTTP header event handling. The CVE was matched to the wrong project."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44ab5f19-2892-51ee-bf1d-9938b8899165",
      "id": "CVE-2020-28500",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-28500 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2020-28500 concerns lodash (a JavaScript utility library) versions prior to 4.17.21, specifically ReDoS vulnerabilities in toNumber, trim, and trimEnd functions. The target repository is on-headers v1.0.2, a completely different Node.js package that provides HTTP header event handling. No relationship exists between the two projects - lodash is not vendored, not a dependency, and the vulner..."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ecc45e-0850-5263-9953-5c740d1ce79d",
      "id": "CVE-2021-23337",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-23337 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2021-23337 is a wrong-project match. The advisory concerns the 'lodash' library's template function command injection vulnerability, but the target repository is 'on-headers' (version 1.0.2), a completely different Node.js package for HTTP header manipulation. Lodash is not present in the repository as the project itself, as vendored code, or as a dependency."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d41bec-7167-511c-84e2-531265ce1cfa",
      "id": "CVE-2022-24999",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-24999 is a false positive for on-headers 1.0.2. false_positive \u2014 CVE-2022-24999 concerns the 'qs' query string parser library, but the target repository is 'on-headers', an HTTP response header listener utility. This is a wrong-project match - the affected component is completely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:npm/on-headers@1.0.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/on-headers@1.0.2"
    }
  ]
}