{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d4701ccb-ee47-54cf-ac86-3d6e1e0c8065",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6",
      "type": "library",
      "name": "@nuxt/kit",
      "version": "4.0.3-tuxcare.6",
      "purl": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8b73a070-7067-5020-a9c6-f22bc5618d19",
      "id": "CVE-2022-21670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-21670 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdaa552f-9971-5b55-b45d-99843556325c",
      "id": "CVE-2022-25852",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/kit 4.0.3-tuxcare.6. CVE-2022-25852 concerns pg-native and libpq (PostgreSQL client libraries for Node.js), but the target repository is Nuxt (a Vue.js meta-framework). Exhaustive containment search found no pg-native/libpq code, no vendored copies, and no dependency relationships. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d3927c1-0d60-5147-94e4-724b4b74c5c2",
      "id": "CVE-2025-59414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59414 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ce62f1-1bb0-5785-98a0-7b156f0e9582",
      "id": "CVE-2026-25128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25128 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e239e01-eb04-54a8-91e1-38cd652cff18",
      "id": "CVE-2026-41305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41305 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c6a93f-f6d2-565c-a031-e641236dd323",
      "id": "CVE-2026-42338",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/kit 4.0.3-tuxcare.6. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm package, but this repository is the 'nuxt' framework. The affected component (ip-address library) is completely absent from the repository - not as the project itself, not as vendored/bundled code, and not as a declared dependency. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50d9968d-2e6e-5b47-ae23-e42109bd5e0f",
      "id": "CVE-2026-44372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44372 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3a9c5a-c19d-566a-9f85-e299b39ea8b6",
      "id": "CVE-2026-45669",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45669 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:605c5551-85e9-5173-9ebf-35b046678f32",
      "id": "CVE-2026-45670",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45670 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a235691-7d6b-575b-9fa3-a66f07c08abc",
      "id": "CVE-2026-45736",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-45736 is a false positive for @nuxt/kit 4.0.3-tuxcare.6. false_positive \u2014 CVE-2026-45736 is a wrong-project match. The advisory concerns the 'ws' WebSocket library for Node.js, but the target repository is Nuxt.js framework. The ws library's source code (specifically lib/sender.js containing the vulnerable WebSocket close implementation) does not exist anywhere in this repository. While ws appears as a transitive dependency in pnpm-lock.yaml, no ws source code is pre..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06d9ec03-cecd-5e3e-aa68-a11bfc7901e7",
      "id": "CVE-2026-46342",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46342 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e295bef-b646-5879-b0b8-06616a1af5e2",
      "id": "CVE-2026-47200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47200 affects version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ef447cc-f1b0-5eb0-a588-e2667408240a",
      "id": "CVE-2026-49993",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49993 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b29a78-b442-54ec-8df9-9c5836bcd152",
      "id": "CVE-2026-53721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53721 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb089a8-f8e2-5266-a492-845dd51e6846",
      "id": "CVE-2026-53722",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53722 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f655507-f12d-501b-b52c-578e4d9947fd",
      "id": "CVE-2026-56326",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56326 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f199918-9192-5d39-b9d4-8d7ff4b1415a",
      "id": "CVE-2026-71314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85ada481-baf5-56ff-a9ad-435dcaca0320",
      "id": "CVE-2026-71316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 4.0.3-tuxcare.6 of @nuxt/kit. Version 4.0.3 is not affected by CVE-2026-71316. The CVE explicitly states the vulnerability was introduced \"From 4.4.0 until 4.5.1\", and the target version (4.0.3) predates this introduction. While the target does handle `_payload.json` requests and has prerender caching mechanisms, the specific vulnerability pattern that allows runtime cache bypass of middleware/guards was introduced in version 4.4.0 and does not exist in version 4.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9392e8ae-0201-56b6-9591-15e6524b1068",
      "id": "CVE-2026-71318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcaa0c82-5c66-5938-8e3f-0d16715827ca",
      "id": "CVE-2026-71320",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71320 affects version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2807b01-f7d5-58d8-a6b3-f5633c62da5c",
      "id": "CVE-2026-71321",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:166efbbd-08e4-5a98-83ef-befe3b6fa560",
      "id": "GHSA-534h-c3cw-v3h9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-534h-c3cw-v3h9 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26715e91-7a10-5848-b255-916dad48088d",
      "id": "GHSA-c9cv-mq2m-ppp3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1078c118-4d95-56b9-81ab-2f276f38bfda",
      "id": "GHSA-m3q2-p4fw-w38m",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m affects version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b9fb990-894a-50bf-ae9d-97175a9d7315",
      "id": "GHSA-rq7w-g337-39qq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-rq7w-g337-39qq is fixed in version 4.0.3-tuxcare.6 of @nuxt/kit."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/kit@4.0.3-tuxcare.6"
    }
  ]
}