{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f87a99d0-2a26-53a2-a960-138477aaf98d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@next/codemod",
      "purl": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6",
      "version": "12.3.7-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-46298",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:94788fbc-fbec-5ec2-b35c-ba39a2a9fac6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46298 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2024-34351",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:196e9014-e73f-5211-9a50-e1b6d12aebdd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34351 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2024-47831",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9c630171-67fe-5f90-b4ab-6a5e1bd107fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47831 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2024-51479",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:50f7e2d4-77a1-5f95-98a3-9441c6f72543",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-51479 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-32421",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d4e0519c-b538-5b3d-b2ba-f47970fe86a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32421 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-48068",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:040b6c65-6ffd-5470-840b-a7a88fd9e0b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48068 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-55173",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:743498fd-7dac-5e18-8cd1-aad81f22fee2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55173 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-57752",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe04577e-f60b-5078-85a7-8eed6020efc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57752 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-57822",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:76169f07-dc2d-514c-8f22-86d7964f7f66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57822 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-59471",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6ccd688c-49c5-5279-a0cb-7c3e5c5fe58b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59471 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2025-59472",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fae0430d-0768-5e62-a90c-33328e5b7f09",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-59472 does not affect version 12.3.7-tuxcare.6 of @next/codemod. not_affected \u2014 Next.js 12.3.7-tuxcare.7 is not affected by CVE-2025-59472. The vulnerability requires Partial Prerendering (PPR) functionality, which was introduced in Next.js 14 and does not exist in version 12.3.7. The vulnerable code path\u2014specifically the PPR resume endpoint that accepts POST requests with the Next-Resume header and processes postponed state data\u2014is entirely absent from this version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-27980",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e064eeab-aebc-5b0f-9ddf-5478da58c2fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27980 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-29057",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a7dc28ae-0a9c-5908-b93b-ea27033ac98c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29057 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44572",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2a7969f4-115e-5a56-91ac-8ffdb141742f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44572 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44573",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:080a6603-9c68-5550-a021-efc6d54e926f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44573 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44577",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1f003fdc-3727-5f12-8d65-e46d3604b9e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44577 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-64645",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:07adadd2-4cbb-5246-b930-14ed4e3852ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-64645 affects version 12.3.7-tuxcare.6 of @next/codemod, and is fixed in 12.3.7-tuxcare.8."
      }
    },
    {
      "id": "GHSA-2xp9-vwfh-vxw4",
      "affects": [
        {
          "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:376456a5-2cc0-5e63-a8af-574d486947f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2xp9-vwfh-vxw4 affects version 12.3.7-tuxcare.6 of @next/codemod."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40next/codemod@12.3.7-tuxcare.6"
    }
  ]
}