{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cdcb8c10-b193-5501-8b46-89bb25833333",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@nuxt/vite-builder",
      "purl": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1",
      "version": "3.2.0-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-25852",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:930b2597-066b-5379-8cf1-5403a312c6f5",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-25852 is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.1. CVE-2022-25852 is a false positive for this repository. The CVE affects pg-native and libpq npm packages (PostgreSQL database client bindings), but this repository is the Nuxt.js web framework (version 3.2.0-tuxcare.4). Exhaustive containment search found no pg-native/libpq code in the repository - not as the project itself, not as a vendored/bundled copy, and not as a declared dependency. This is a wrong-project match."
      }
    },
    {
      "id": "CVE-2024-34343",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e14095d-94e6-5d5a-88ff-90a51bf7e25a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34343 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder, and is fixed in 3.2.0-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-24361",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:41aa1c6a-f904-5cda-bcba-81690101a589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24361 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder, and is fixed in 3.2.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-27415",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:05867743-eb22-5457-a9bc-a2552ff37272",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27415 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      }
    },
    {
      "id": "CVE-2026-41305",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6fb29a88-f150-5122-94ec-6630b43812e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41305 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      }
    },
    {
      "id": "CVE-2026-42338",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ef467a9-790a-5a5f-82c1-e5701df419be",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-42338 is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.1. false_positive \u2014 CVE-2026-42338 concerns the 'ip-address' npm library (IPv6/IPv4 address parsing), but this repository is Nuxt v3.2.0-tuxcare.1 (a Vue.js meta-framework). The affected component is not present in this repository as a vendored copy, dependency, or in any other form. This is a wrong-project match."
      }
    },
    {
      "id": "CVE-2026-45669",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dc8f4c5a-93b6-5c06-9775-0c8a913fc59d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45669 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected - CVE-2026-45669 requires the SSR redirect body that navigateTo(url, {external:true}) builds in packages/nuxt/src/app/composables/router.ts (nuxtApp.ssrContext['~renderResponse'] with only the double quote percent-encoded). In nuxt 3.2.0 that code does not exist: the server-side external branch of navigateTo delegates to h3 sendRedirect(event, redirectLocation, code) and builds no HTML body. Grep over the branch: '%22' - 0 hits in source, 'renderResponse' - only packages/nuxt/src/core/runtime/nitro/renderer.ts. The sink appears in later majors: 4.0.3 has it and carries patches/CVE-2026-45669.patch."
      }
    },
    {
      "id": "CVE-2026-46342",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e2fd9159-8651-5644-b8b2-76832f810aee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46342 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      }
    },
    {
      "id": "CVE-2026-47200",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28f78f22-7f02-50db-bf74-77845b9abc86",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47200 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Nuxt version 3.2.0 does not contain the server-only pages feature that is the prerequisite for CVE-2026-47200. The vulnerable code pattern (`.server.vue` pages rendered as islands via `/__nuxt_island/page_*` endpoint) was introduced in Nuxt v3.11.0, which is 2,059 commits after v3.2.0. The target version predates the feature by multiple major versions.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-53722",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2760aa5f-9283-5763-9d7d-895838040bba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53722 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder, and is fixed in 3.2.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-56317",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34e55687-01ef-52fd-af94-bda89c06ad97",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56317 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder, and is fixed in 3.2.0-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-56326",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:21fad708-6032-5607-b508-deb80b2fd56f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56326 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 does not contain the vulnerable code pattern. The vulnerability exists in the encodeURL() function which was introduced on June 26, 2024, over a year after version 3.2.0 (released February 9, 2023). The target uses a simpler redirect architecture without the vulnerable encodeURL() function.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-71314",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:431ceab0-0dd1-5458-b2a6-5022820cadc7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71314 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      }
    },
    {
      "id": "CVE-2026-71316",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:917ea3ef-05b2-5ac0-8824-835062b00fab",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-71316 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. Nuxt.js version 3.2.0 is not affected by CVE-2026-71316. The vulnerability requires runtime payload caching (introduced in Nuxt 4.x) where _payload.json entries are served before route middleware. Version 3.2.0 only has build-time prerender cache (null during runtime), uses _payload.js files (not .json), and all runtime payload requests undergo full SSR rendering with route rules enforcement. The vulnerable code path (runtime cache bypass) does not exist in this version's architecture.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-71318",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aa0c1430-715a-5ee8-bded-b03bdbae14ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71318 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      }
    },
    {
      "id": "CVE-2026-71321",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7a8c37ee-6c2e-591a-8f62-ce81a38c7c3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-71321 affects version 3.2.0-tuxcare.1 of @nuxt/vite-builder."
      }
    },
    {
      "id": "GHSA-c9cv-mq2m-ppp3",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33cb0087-eb77-5b97-b550-8c77b21df372",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c9cv-mq2m-ppp3 does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Target repository Nuxt version 3.2.0 is NOT affected by GHSA-c9cv-mq2m-ppp3. All three vulnerability sinks described in the CVE (SSR open redirect via path-normalization, script execution via navigateTo open option, and protocol-relative bypass in reloadNuxtApp) require code features that were introduced AFTER version 3.2.0. The vulnerable encodeURL function with WHATWG URL parsing was added in...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-m3q2-p4fw-w38m",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:32045473-1281-5757-8753-87960bcbf9b7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m3q2-p4fw-w38m does not affect version 3.2.0-tuxcare.1 of @nuxt/vite-builder. not_affected \u2014 Version 3.2.0 is NOT affected by GHSA-m3q2-p4fw-w38m. The vulnerable innerHTML pattern was introduced in v3.16.0 (March 2025), two years after this version. The target uses noscript.children instead of the vulnerable noscript.innerHTML assignment.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-xppm-jmw6-fhmf",
      "affects": [
        {
          "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9ef61c42-8852-570b-98db-a1d807ee8be9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-xppm-jmw6-fhmf is a false positive for @nuxt/vite-builder 3.2.0-tuxcare.1."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40nuxt/vite-builder@3.2.0-tuxcare.1"
    }
  ]
}