{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:adf556ee-2d93-529d-92de-0d8aad1635c5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@next/third-parties",
      "purl": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7",
      "version": "16.0.6-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "@base-ui-components__react@1.0.0-beta.1",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2c72a371-17fb-577d-8cc5-7a5becc4d968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability @base-ui-components__react@1.0.0-beta.1 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2025-55182",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9c7fc6b6-dcf8-5ac6-891c-c1802504d873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55182 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2025-59471",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3041f966-d578-5290-8b8b-3075e167bd08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59471 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2025-59472",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e6859cb2-9c57-52c6-9b03-c80de7829b00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59472 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-27977",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e4dd0803-0a4b-5c1a-b8e8-46532861b2d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27977 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-27978",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c8c4158e-5d3b-57b2-85fa-ba375dda5efe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27978 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-27979",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:77cfb22b-b6bf-5424-8488-f939ac4bc292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27979 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-27980",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:20648f82-b0a2-585c-8e9a-9bf188d55099",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27980 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-29057",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4d5cc987-bcd0-5a48-be90-d7cba643f4b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29057 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44572",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bf786f9b-f8e8-5012-a296-e4f9aa98f6a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44572 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44573",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1ff1a83f-e904-5cb2-b10d-21aed6cd168d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44573 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44574",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bea866b5-a0e4-52b7-b21e-abb2e4479fb9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44574 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44575",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7eb31cbc-1374-5521-b4c8-729a9ab1b4a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44575 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44576",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3f3b2693-641c-529c-ba86-e2b18f15901e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44576 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44577",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:003a5290-0b72-51a8-b424-1914dbb1efb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44577 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44578",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3abedd03-3a56-5e6d-a66f-69e87b21f48b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44578 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44579",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1afdb5ba-9d08-58f4-bf75-c34b18e07e1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44579 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44580",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f3b79aa1-b052-5bed-ae6c-c651554ee94c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44580 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44581",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:63450cf2-0e28-5176-806e-7ba9f1211967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44581 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-44582",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a4c5b3be-ee03-5755-be5e-a2afcfd7ce14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44582 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "CVE-2026-75604",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1934f38c-8206-5976-bbcf-635e622127a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-75604 affects version 16.0.6-tuxcare.7 of @next/third-parties, and is fixed in 16.0.6-tuxcare.9."
      }
    },
    {
      "id": "GHSA-2xp9-vwfh-vxw4",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:64eebe84-592b-5f72-ba05-8a45bcc5aa0f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2xp9-vwfh-vxw4 affects version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "GHSA-8h8q-6873-q5fj",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0eadf424-e57b-5b11-bc13-3c2544e9fac4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8h8q-6873-q5fj is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "GHSA-9qr9-h5gf-34mp",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0c4cfc91-a1b9-578e-b582-5fdd0ad96247",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-9qr9-h5gf-34mp is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "GHSA-h25m-26qc-wcjf",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:073eeb46-813f-5332-9d59-ac24a7af5ba2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h25m-26qc-wcjf is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "GHSA-mwv6-3258-q52c",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1d525c1f-a991-504a-a41e-b7ad67c41758",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mwv6-3258-q52c does not affect version 16.0.6-tuxcare.7 of @next/third-parties. Target version 16.0.6 is NOT AFFECTED. The target uses React version 52684925-20251110 (November 10, 2025), which predates the introduction of the vulnerable code by one month. The vulnerability (unbounded for loop in ReactPromise.prototype.then causing infinite CPU consumption during thenable chain inspection) was introduced in commit 4e20596af8 with React c689797a-20251209 (December 10, 2025) and fixed in commit 9a0dc9c555 with React 419bf4ac-20251211 (December 11, 2025). The target's React implementation does not contain the vulnerable code pattern, so the attack path from malicious serialized data to server hang does not exist.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-q4gf-8mx6-v5v3",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:db353eee-3d06-5eb1-b7b4-4f01ad4ceb8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-q4gf-8mx6-v5v3 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "GHSA-w37m-7fhw-fmv9",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9797d295-b8bc-50f8-b99f-75555e43c3b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-w37m-7fhw-fmv9 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "stacktrace-parser@0.1.10",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fecc0fa0-3f2e-5507-a7bd-6bac76ae816a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability stacktrace-parser@0.1.10 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "taskr@1.1.0",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8ce4d1f2-34ee-5c87-9e12-4f012edb4a24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability taskr@1.1.0 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "@types__node@20.17.6",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:127f84c2-b57b-502d-9c55-f1112b718818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability @types__node@20.17.6 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    },
    {
      "id": "webpack-sources@3.2.3",
      "affects": [
        {
          "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7d09916b-2fd0-536c-96da-11e5bde35b71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability webpack-sources@3.2.3 is fixed in version 16.0.6-tuxcare.7 of @next/third-parties."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40next/third-parties@16.0.6-tuxcare.7"
    }
  ]
}