{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:22b42547-5cd5-598d-803d-1ee6e68a606e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1",
      "type": "library",
      "name": "protobufjs",
      "version": "5.0.3-tuxcare.1",
      "purl": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:11bc6af0-dd0b-5af7-a3ba-c15cc258f066",
      "id": "CVE-2022-25883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25883 is fixed in version 5.0.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53aad1ee-e267-56c3-9211-d7693f7e5df4",
      "id": "CVE-2026-29063",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29063 is fixed in version 5.0.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c98d28-31bb-5bae-86af-00afbd98dbfe",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41242 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 analysis-only patch file patches/CVE-2026-41242.patch on tuxcare-current/5.0.3 in els-js/protobufjs documents that CVE-2026-41242 does not affect this version (no code change applied)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ca47a0-ec9f-58fd-a75c-638f2d198a96",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44288 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.3 of protobufjs is not affected by CVE-2026-44288. The vulnerability exists in protobufjs's minimal UTF-8 decoder (lib/utf8/index.js) which was introduced in version 6.6.2. Version 5.0.3 uses a fundamentally different architecture, delegating all UTF-8 encoding/decoding operations to the external ByteBuffer library (~5), and does not contain the vulnerable code component."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67807c50-7f8e-5148-b964-62340b73d303",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 5.0.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:118c3128-9bf2-5cf0-ba26-cdaec101a4e6",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 analysis-only patch file patches/CVE-2026-44290.patch on tuxcare-current/5.0.3 in els-js/protobufjs documents that CVE-2026-44290 does not affect this version (no code change applied)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5772b571-a465-582e-82c1-9d2b5dac897f",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44291 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 analysis-only patch file patches/CVE-2026-44291.patch on tuxcare-current/5.0.3 in els-js/protobufjs documents that CVE-2026-44291 does not affect this version (no code change applied)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0354f66e-eafe-5b6f-8a09-7c0010391bbc",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44292 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 analysis-only patch file patches/CVE-2026-44292.patch on tuxcare-current/5.0.3 in els-js/protobufjs documents that CVE-2026-44292 does not affect this version (no code change applied)."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adf59605-1d1b-5610-96ec-e33a0c93cf75",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44293 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.3 of protobufjs is not affected by CVE-2026-44293. The vulnerability exists in the static code generation infrastructure (src/converter.js) which generates toObject conversion methods with unsafe string interpolation of bytes field default values. This code generation feature was introduced in version 6.4.0, well after version 5.0.3. Version 5.0.3 uses only runtime-based message con..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77de7c4f-236f-5626-901b-cd3456bcc661",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44294 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.3 uses a fundamentally different architecture than the vulnerable versions 6.x/7.x. The vulnerability requires static code generation that embeds field names as JavaScript identifiers, which does not exist in version 5.x. Version 5.x uses JSON serialization (which auto-escapes control characters) and runtime bracket notation for property access, neither of which can produce the vuln..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a6fe60-3c06-5a0a-8cad-27aea0df94f9",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 5.0.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52b7316e-c255-5ad1-aee5-40cfb6cc6330",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 5.0.3-tuxcare.1 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88113dc5-9092-5e19-8c8d-f256e1104199",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54269 does not affect version 5.0.3-tuxcare.1 of protobufjs. CVE-2026-54269 fix already exists in commit 89c1b9784acffee13688b2324852f0be765961d1"
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acc49f6d-4803-516b-b78e-d7aade7bdefc",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 protobufjs version 5.0.3 is not affected by CVE-2026-54270. The vulnerability requires unknown field preservation functionality that was introduced in version 8.2.0, which is absent from version 5.0.3. The target version discards unknown fields during decode and has no mechanism to retain them in memory."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf930b5-e9fb-5b73-82c0-a35e135b306e",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 CVE-2026-59876 affects the optional Text Format extension (protobufjs/ext/textformat) which does not exist in protobufjs version 5.0.3. The target uses a different architecture where text format parsing for protobuf DATA is not implemented. Only binary and JSON input paths are supported, which the CVE explicitly states are not affected."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f977c2f2-a8a3-5bea-93c5-ebea110b033e",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 5.0.3-tuxcare.1 of protobufjs. not_affected \u2014 Version 5.0.3 is not affected by CVE-2026-59877. The vulnerability exists in versions 6.x/7.x which use a different code architecture with a `while (token !== \"=\")` loop in `src/parse.js`. Version 5.0.3 uses `src/ProtoBuf/DotProto/Parser.js` with a `skip('=')` method that inherently checks for EOF and throws an error instead of looping indefinitely. The vulnerable code pattern does not exist in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@5.0.3-tuxcare.1"
    }
  ]
}