{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:97a38957-f3cb-5599-baed-05b8da934167",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3",
      "type": "library",
      "name": "protobufjs",
      "version": "6.10.2-tuxcare.3",
      "purl": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3804e42b-9330-5aaa-83a4-de4ab43db76d",
      "id": "CVE-2022-25878",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25878 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cf9b800-8e6a-5bb3-9305-35725d829c5a",
      "id": "CVE-2023-36665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36665 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b08efd-411b-59be-a16e-b94c9f555e89",
      "id": "CVE-2026-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d39950-cede-5968-b241-e221e6443780",
      "id": "CVE-2026-44288",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44288 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee7da3a-40a2-5e09-847d-6c7583651a9f",
      "id": "CVE-2026-44289",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f702a46f-51d5-501c-b273-24f3f9759307",
      "id": "CVE-2026-44290",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 6.10.2-tuxcare.3 of protobufjs. CVE-2026-44290 fix already exists in commit f87c65fb1bedc7be0ee2504542878b86ee943218"
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d2a2c4e-ee1e-5a4b-b2ce-2b3d686be172",
      "id": "CVE-2026-44291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44291 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f7fc83-358d-5138-afe8-3db075e1a9e1",
      "id": "CVE-2026-44292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44292 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:682f014c-250f-5847-88e0-2360a8e1b19c",
      "id": "CVE-2026-44293",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44293 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6eb1280-4549-5498-b8cb-eb8632624e33",
      "id": "CVE-2026-44294",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44294 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4922fd-092a-52fd-b695-4fd6f01b47e7",
      "id": "CVE-2026-45740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e47fba36-cafc-5d0f-8876-fade11f6c4eb",
      "id": "CVE-2026-48712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e120db8-6674-5a81-8d10-e6f531365e29",
      "id": "CVE-2026-54269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.10.2-tuxcare.3 of protobufjs."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83fb58b1-12f6-5651-aead-0d89605b3045",
      "id": "CVE-2026-54270",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.10.2-tuxcare.3 of protobufjs. not_affected \u2014 Target version 6.10.2 is not affected by CVE-2026-54270. The vulnerability concerns excessive memory retention from unknown field preservation, a feature introduced in protobufjs 8.2.0. Version 6.10.2 does not implement unknown field preservation; unknown fields are simply skipped during decode without storing them in memory."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4055b03-7a92-5add-b6b4-c7fd46c342a8",
      "id": "CVE-2026-59876",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.10.2-tuxcare.3 of protobufjs. not_affected \u2014 CVE-2026-59876 specifically affects the optional Text Format extension (ext/textformat.js) which does not exist in protobufjs version 6.10.2. This extension was introduced as a new feature in version 8.x. Without the Text Format extension, the attack vector described in the CVE cannot be exploited."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:559935dc-9b39-59ab-8326-31d213a2ebb9",
      "id": "CVE-2026-59877",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.10.2-tuxcare.3 of protobufjs. not_affected \u2014 Version 6.10.2 is not affected by CVE-2026-59877. The vulnerable code pattern (a while loop advancing through tokens looking for '=' without EOF checking) does not exist in this version. Version 6.10.2 uses a different architecture with skip('=') that properly handles EOF by throwing an error."
      },
      "affects": [
        {
          "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/protobufjs@6.10.2-tuxcare.3"
    }
  ]
}