{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c0652ab6-5455-54cc-ae9f-7e01c3f49df7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "3.8.2-tuxcare.1",
      "purl": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:220575eb-31df-5d68-9e9e-e1b13b79e615",
      "id": "CVE-2018-3738",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3738 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57075258-38c9-55e3-93f3-f3af1c5e30ec",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b4234e2-c293-5220-b858-f7b605d130f9",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44288 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:521bd34a-7d03-5b51-a610-13b26c99cd37",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98c0e4a3-b7ac-59ad-8e55-6ce6b8d5a759",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44290 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:822f5153-9e8b-58b3-8c1c-f2027ae33387",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44291 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95dc0bcd-afeb-5e80-bc2f-6e744a706065",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44292 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84878e35-386f-5414-a585-db600395ea77",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44293 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71114053-44cc-58a2-8f52-707125fda30a",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44294 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca8f0cd-1b2b-54ff-b00e-b348c9014c96",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:027b50ee-1ec0-5e37-9db7-e0e896b3b985",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be65ac9b-4d66-5ed8-af1c-b214528c7c56",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54269 is fixed in version 3.8.2-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2fa520-8773-5639-b357-bd6a3970ee93",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 3.8.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 3.8.2 is not affected by CVE-2026-54270. The vulnerability requires the unknown field preservation feature introduced in protobufjs 8.2.0, which does not exist in this version. Version 3.8.2 always discards unknown fields during decode by advancing the buffer position without retaining the data."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a38318-9fe2-52a6-bb81-f0da79cbd24d",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 3.8.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 3.8.2 does not contain the Text Format extension or map field support. The vulnerability requires parsing protobuf text format input with string-keyed map fields using ext/textformat.js, which does not exist in this version. This is a proto2-only implementation from 2014 that predates the affected features."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4712c10-a389-57fd-b7bc-ae2ee500a3bf",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 3.8.2-tuxcare.1 of protobufjs. not_affected \u2014 Version 3.8.2 is not affected by CVE-2026-59877. The vulnerability requires a 'while (token !== \"=\")' loop in option parsing that can run indefinitely when EOF is reached. Version 3.8.2 uses a fundamentally different architecture with sequential token consumption and immediate validation, making the infinite loop pattern impossible."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e2c5cbb-bd00-53ab-a5fa-48d6df95a611",
      "id": "GHSA-4gpv-cvmq-6526",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4gpv-cvmq-6526 is a false positive for protobufjs 3.8.2-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@3.8.2-tuxcare.1"
    }
  ]
}