{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:efb5732d-d86e-58e4-9a81-b3aee81fbb30",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@next/font",
      "purl": "pkg:npm/%40next/font@16.0.6-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3",
      "version": "16.0.6-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "@base-ui-components__react@1.0.0-beta.1",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:50019690-6dbf-5fc3-a187-1f0784480abd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability @base-ui-components__react@1.0.0-beta.1 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-55182",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7d519b9b-5631-5338-aba0-831769e9ba77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55182 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-59471",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e196cc57-3a65-5641-96d8-5afabbe21031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59471 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "CVE-2025-59472",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5a7d38a6-720c-5718-b914-69b99b3b3525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59472 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27977",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:edcdc057-912a-58f7-ad40-73d1cc161217",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27977 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27978",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:61730848-3ec1-5a49-a79b-101f4d337a56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27978 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27979",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:20fd1f66-97c6-5407-8f4e-101b62d99f10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27979 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27980",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:01c66314-bf9f-517c-95f6-8c6773b0d8ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27980 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-29057",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6ceffd2d-d725-531b-8871-bf90e8fb92ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29057 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-44572",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7cb313b5-907f-5c19-b0c0-b07304d99a0c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44572 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-44573",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:814f3980-2aa1-50a2-a090-c4f303bc11c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44573 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-44574",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:77ca425f-d26d-5b11-8bbe-ff60cac5a48c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44574 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44575",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e5ecdc84-fc1f-57b5-aa64-0341822e8eee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44575 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44576",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fdf202f5-2cf0-504a-b903-e2c115b23bbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44576 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44577",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d3a7f1b3-6103-5a9a-a197-bf774dc9d7a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44577 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44578",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1eb55384-f237-54b0-9be7-a7704bfa30a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44578 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44579",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cf58cced-90ce-5935-844d-cff22d5e9131",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44579 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44580",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a603661f-ee17-54ec-9d56-08ae9b6d5d1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44580 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44581",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fa41a1fd-b98d-567e-8d76-7ec5ec97729c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44581 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-44582",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:11c4680a-3341-5de0-9a11-16128d3fa7df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44582 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-75604",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:329e797a-2fb7-58f7-972b-d43f2f379ae6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75604 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.9."
      }
    },
    {
      "id": "GHSA-2xp9-vwfh-vxw4",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2b85b713-da19-566d-8ac2-2ec89a862a1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2xp9-vwfh-vxw4 affects version 16.0.6-tuxcare.3 of @next/font."
      }
    },
    {
      "id": "GHSA-8h8q-6873-q5fj",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cc246e2b-a5fd-551e-87be-e8b318e02773",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8h8q-6873-q5fj affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "GHSA-9qr9-h5gf-34mp",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a05efd78-db44-5b11-a484-185832a1f7bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-9qr9-h5gf-34mp is fixed in version 16.0.6-tuxcare.3 of @next/font."
      }
    },
    {
      "id": "GHSA-h25m-26qc-wcjf",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:33959115-9b3f-58fc-8076-26e0737b2a5c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h25m-26qc-wcjf affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "GHSA-mwv6-3258-q52c",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5148e967-2898-5954-a2f4-a9c89312dd80",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mwv6-3258-q52c does not affect version 16.0.6-tuxcare.3 of @next/font. Target version 16.0.6 is NOT AFFECTED. The target uses React version 52684925-20251110 (November 10, 2025), which predates the introduction of the vulnerable code by one month. The vulnerability (unbounded for loop in ReactPromise.prototype.then causing infinite CPU consumption during thenable chain inspection) was introduced in commit 4e20596af8 with React c689797a-20251209 (December 10, 2025) and fixed in commit 9a0dc9c555 with React 419bf4ac-20251211 (December 11, 2025). The target's React implementation does not contain the vulnerable code pattern, so the attack path from malicious serialized data to server hang does not exist.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-q4gf-8mx6-v5v3",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9175ab47-02d2-5063-aeeb-ba99be1098b3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-q4gf-8mx6-v5v3 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "GHSA-w37m-7fhw-fmv9",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:bb6cf289-4f30-5da0-8fd3-ffc31de8eaef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-w37m-7fhw-fmv9 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.6."
      }
    },
    {
      "id": "stacktrace-parser@0.1.10",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4564d6d9-fc3c-5980-9231-f79271c565da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability stacktrace-parser@0.1.10 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "taskr@1.1.0",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:72c655be-c483-54b3-8d98-548416e57802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability taskr@1.1.0 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "@types__node@20.17.6",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:de6dc520-4637-5295-ad1f-b0279cddfd85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability @types__node@20.17.6 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    },
    {
      "id": "webpack-sources@3.2.3",
      "affects": [
        {
          "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d96ba572-10e3-5f74-945e-057eadf7dada",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability webpack-sources@3.2.3 affects version 16.0.6-tuxcare.3 of @next/font, and is fixed in 16.0.6-tuxcare.5."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40next/font@16.0.6-tuxcare.3"
    }
  ]
}