{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6e7bba24-3908-5c64-8f3a-3ff46fe63a2a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/axios@1.7.9-tuxcare.4",
      "type": "library",
      "name": "axios",
      "version": "1.7.9-tuxcare.4",
      "purl": "pkg:npm/axios@1.7.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4b37224d-8bbd-5452-8387-571ba99745a8",
      "id": "CVE-2020-7676",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7676 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cb77719-5a85-5f18-b238-450f32a00602",
      "id": "CVE-2022-25844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25844 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68f2641a-aa16-50da-a355-1b56fb847696",
      "id": "CVE-2022-25869",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25869 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc1a7f2b-2223-501b-92c3-b213f5ef2add",
      "id": "CVE-2023-26116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26116 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f741a763-3b18-5537-959b-882e99ed9230",
      "id": "CVE-2023-26117",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26117 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:211bfc95-cc40-5aff-b86d-de50ee928496",
      "id": "CVE-2023-26118",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26118 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a20896f-b36d-5847-b9dc-74dacb09345f",
      "id": "CVE-2024-21490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21490 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d9ffc4-ad64-58bd-a53e-840318005d1c",
      "id": "CVE-2024-8372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8372 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2151b272-a83e-5f09-b81f-14cf7ceaf393",
      "id": "CVE-2024-8373",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8373 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3e938db-8b46-51ba-85e3-72692416c87b",
      "id": "CVE-2025-0716",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-0716 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aa63621-d440-5435-a455-024ce5f2e8cb",
      "id": "CVE-2025-2336",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-2336 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828ae899-2995-57cf-ad28-0ba3540ccbdf",
      "id": "CVE-2025-27152",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc78adb-5a3e-5998-86db-2c004a0d748d",
      "id": "CVE-2025-4690",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-4690 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b107321-d21f-541a-979d-f9ee4aba12b2",
      "id": "CVE-2025-58754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e73896e-440c-5b10-bcc1-602ffc8a4a9b",
      "id": "CVE-2025-62718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852705d0-8f13-5324-b54d-8f6d0400d5da",
      "id": "CVE-2026-25639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.7.9-tuxcare.4 of axios. Version 1.7.9 is not vulnerable. Summary: The target repository (axios v1.7.9) is NOT vulnerable to CVE-2026-25639. The target uses Object.assign({}, config1, config2) for key iteration, which does not include __proto__ in Object.keys() results, preventing the DoS crash. The vulnerable code pattern was introduced later in v1.11.0 when the code was refactored to use the spread operator ({...config1, ...config2}). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2871595f-eec8-5c8e-a306-c48e4504106b",
      "id": "CVE-2026-40175",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8fe8b7-8c8d-5069-95fd-c6a880fb7b4c",
      "id": "CVE-2026-42033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2b2407a-e78d-58fd-96d3-32145b551cb8",
      "id": "CVE-2026-42034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4cfba96-0cae-55df-b085-c534b4d8f1cb",
      "id": "CVE-2026-42035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c8809f0-5ca1-5e15-b402-413f77939291",
      "id": "CVE-2026-42036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66af6359-9531-5393-9caa-b3a1955ed9c8",
      "id": "CVE-2026-42037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc6c4f27-4c15-5de0-aa40-c9fe5de9aa35",
      "id": "CVE-2026-42038",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea7f5d9-4eef-52c8-b0d4-c741ba477f1c",
      "id": "CVE-2026-42039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8d7c681-3185-5262-80d1-98cab639bad6",
      "id": "CVE-2026-42040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c42816b6-a60f-5ab3-afd4-d1194f8b8924",
      "id": "CVE-2026-42041",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4e7c984-362f-55ce-8f0c-95971aa78bf8",
      "id": "CVE-2026-42042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cd2eace-a461-5551-b27c-ff16dfb08733",
      "id": "CVE-2026-42043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.7.9-tuxcare.4 of axios. Version 1.7.9 is not vulnerable. Summary: The target version (axios v1.7.9) is NOT vulnerable to CVE-2026-42043 because the vulnerable shouldBypassProxy feature does not exist in this version. The target uses the external 'proxy-from-env' package for proxy handling, whereas the vulnerability exists in axios's own shouldBypassProxy implementation that was only introduced in version 1.15.0. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:345473b6-c9e2-5523-8b0e-fd7acedd320c",
      "id": "CVE-2026-42044",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b98e9a-4fb2-563b-81e4-061df6ffa4e5",
      "id": "CVE-2026-42264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd3954dd-7043-5415-ba4f-cbd6a2561234",
      "id": "CVE-2026-44486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b65dc94d-96b4-5d2c-a736-2b3803671caa",
      "id": "CVE-2026-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb10e2a6-d8fb-5c3e-8978-a0eb4519eb32",
      "id": "CVE-2026-44488",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44488 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf51430-1039-5084-8852-081216404ddc",
      "id": "CVE-2026-44490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca055852-38b6-53f9-986f-107e52169a9b",
      "id": "CVE-2026-44492",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eef7d97f-9edb-5542-89b5-df0422ca25fe",
      "id": "CVE-2026-44494",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44494 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5aba46-6bf8-5758-bdc7-3df4d971599a",
      "id": "CVE-2026-44495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44495 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb15ea84-a302-5334-b996-b7da260c47a5",
      "id": "CVE-2026-44496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52b57d37-92fe-5d03-b644-f10706b6fc80",
      "id": "CVE-2026-67312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67312 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ed0ab3d-6213-5481-888e-96ad467fcda9",
      "id": "CVE-2026-67313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67313 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58df8c77-928f-5ad9-bbbd-12e67feb62e1",
      "id": "CVE-2026-67316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67316 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d0c68e-23f5-5497-b679-fcfba20a6074",
      "id": "CVE-2026-67317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67317 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69e3b969-edaf-5ffc-b9ba-48bd155e11d4",
      "id": "CVE-2026-67319",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67319 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee76b93-ecb7-5696-a260-3c00449653f0",
      "id": "GHSA-42h9-826w-cgv3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88f7c6c7-1327-5153-b31f-55a40a714528",
      "id": "GHSA-4ww2-rjh2-xpv9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4ww2-rjh2-xpv9 is a false positive for axios 1.7.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fadf3f8-d4b5-534b-8e27-23d274a63425",
      "id": "GHSA-7q8q-rj6j-mhjq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf101977-35b3-5795-8fc5-80433b9669c7",
      "id": "GHSA-jqh4-m9w3-8hp9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jqh4-m9w3-8hp9 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2d113f3-b808-5735-8402-9c50ea8712ca",
      "id": "GHSA-mmx7-hfxf-jppx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c08ae6f6-41ff-5a17-841f-092e59789cab",
      "id": "GHSA-pmv8-rq9r-6j72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 is fixed in version 1.7.9-tuxcare.4 of axios."
      },
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.7.9-tuxcare.4"
    }
  ]
}