{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3078c51f-3925-57a1-8315-f6c4e0a35a12",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "4.1.3-tuxcare.1",
      "purl": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6954c95b-b0c8-55d4-b0a4-dff64e17ca0e",
      "id": "CVE-2018-3738",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-3738 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0af5ddf0-1a12-5710-9c2d-114d041cf5cf",
      "id": "CVE-2019-8331",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-8331 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78174cdd-4ec1-52a4-9c33-cb2bd5142b9c",
      "id": "CVE-2025-8101",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-8101 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:941d7f9b-d296-53a4-9234-1cbc59158c34",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41242 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 is not affected by CVE-2026-41242. The vulnerability requires code generation mechanisms introduced in version 6.x+ that do not exist in the 4.x architecture. Type names are only used for safe property access and error messages, with no path to arbitrary code execution."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e78b093b-30fc-5470-9c5f-6aa13439aead",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44288 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 uses a fundamentally different architecture than the affected versions (6.x/7.x). The vulnerable component (protobufjs's minimal UTF-8 decoder in lib/utf8/index.js and src/util/utf8.js) does not exist in version 4.1.3, which exclusively uses the ByteBuffer.js library for all UTF-8 string decoding operations. TuxCare backported the CVE-2026-44288 fix to version 6.11.6 but not to 4...."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6214d5ef-ebd8-56e5-988f-b283ded32b57",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b596d2-b1e7-5503-8d9a-add321566b63",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 analysis-only patch file patches/CVE-2026-44290.patch on tuxcare-current/4.1.3 in els-js/protobufjs documents that CVE-2026-44290 does not affect this version (no code change applied)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c367541e-28c9-591a-a6ee-32be1cd38d31",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44291 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 analysis-only patch file patches/CVE-2026-44291.patch on tuxcare-current/4.1.3 in els-js/protobufjs documents that CVE-2026-44291 does not affect this version (no code change applied)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06569578-b985-5d1b-a824-43abac17c4b0",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44292 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 uses a different architecture from the patched versions 6.x/7.x. While it processes objects with enumerable properties including __proto__, the message constructor and creation helpers (decodeJSON, encode) validate field names and throw an error when __proto__ is encountered, preventing prototype chain modification. The vulnerability pattern described in CVE-2026-44292 does not ap..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e29109a2-9e08-5b58-82e4-a3264e0ef130",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44293 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 uses a fundamentally different architecture (pure runtime model) than the vulnerable upstream version (7.x static code generator). The CVE-2026-44293 vulnerability exists in static code generation where bytes field default values are unsafely embedded into generated JavaScript using raw string substitution. Version 4.1.3 has no static code generator and processes descriptors entir..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b6f1558-aee8-5f39-a03e-4df243414dc0",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44294 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 uses runtime property access without code generation, making the vulnerability pattern inapplicable. The CVE specifically concerns control characters causing syntax errors when embedded into generated JavaScript function bodies. Version 4.1.3 does not generate code from field names and therefore cannot exhibit the described vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25c5559b-b111-5926-a175-8bd58811c241",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff98f87-3fea-5330-87ec-094fceb3e6d3",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93105ff6-af34-5082-b1b3-8d004495c55d",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54269 is fixed in version 4.1.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5055c06-27e0-5996-a64b-fc09ed738959",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Target version 4.1.3 is NOT affected by CVE-2026-54270. The vulnerability concerns unknown field preservation introduced in protobufjs 8.2.0, a feature that does not exist in version 4.1.3. The target discards unknown fields during decode without storing them, preventing the memory exhaustion attack described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e36b8c92-f59d-5e14-9577-946c0024a27f",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 does not contain the vulnerable Text Format extension. The CVE-2026-59876 vulnerability is specific to protobufjs/ext/textformat, which was introduced in later versions (6.x+). Version 4.1.3 only supports binary decode and ProtoJSON/fromObject input paths, which the CVE explicitly excludes from the vulnerability scope."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c11312-d1f4-58fa-b222-bcd76b7d917b",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 4.1.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 4.1.3 uses a different parser architecture (DotProto module) that does not have the vulnerable while loop pattern. The _parseOption function calls this.tn.skip('=') directly instead of using a loop to search for the '=' token, so EOF causes an immediate error throw rather than an infinite loop."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d71381-7f6e-5398-8725-3b6c9d249513",
      "id": "GHSA-4gpv-cvmq-6526",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4gpv-cvmq-6526 is a false positive for protobufjs 4.1.3-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@4.1.3-tuxcare.1"
    }
  ]
}