{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:487b15f4-fd49-5626-b30e-200a614642f0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@0.21.1",
      "type": "library",
      "bom-ref": "pkg:npm/axios@0.21.1",
      "version": "0.21.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-3749",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:8fbe6db5-6f99-59ec-a806-37faa69a8981",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-3749 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2023-45857",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:29216335-4215-5441-96df-6c9b18c58458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-45857 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2024-39338",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:7538f208-8734-5e86-9ed9-cdfd84916524",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.21.1 of axios. already_fixed \u2014 The target axios 0.21.1-tuxcare.1 already contains equivalent defense logic against CVE-2024-39338 (protocol-relative URL SSRF) through the 'allowAbsoluteUrls' parameter added in CVE-2025-27152 backport (commit bc6d5a0b). When set to false, this parameter forces baseURL concatenation for protocol-relative URLs, preventing SSRF. The defense code exists in the codebase and is reachable on all exe...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:58559e70-1ed2-5967-bcd2-6b883cca9442",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27152 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:5c186518-329d-5938-8f65-74739fbc8234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:9c1ac687-c94e-5ee1-a6c0-a1e819e2f8b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25639 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:fb3f86dc-5990-5733-826b-a6486c0d3e02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:a3bb2aa8-3d5c-59cf-8f14-db5695c0affc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:adedfec4-f84c-5c87-bc6b-50bb90d97ce3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:fcee0b64-d7d1-5a69-9e46-e6d58d09e3fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:6b2e00aa-b69b-598d-9189-68fa860b06d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:e5534588-c1ce-5469-bbbe-4d1ebc87147f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:0f40559a-e393-56c9-b11f-604060fb2ad7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42039 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:e7d134cf-f74a-5aa4-9eb9-95a9dfba853c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:448e4b93-5c6f-549b-b2db-0e108fc36364",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:b16688ca-202d-5012-83fe-de126f19c41b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:e9ae5dd1-72cc-5900-a90d-3eb15fb95001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:ae4b43ef-78ac-51af-afcd-e8adcfa07371",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:1fcf38ea-7e3a-5174-9c15-8ad08fe3f765",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:33c2d93f-414e-569d-b2b5-4e1f9d868aac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:263dd683-b9b4-5406-a8f5-da45b9af33c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.21.1 of axios."
      }
    },
    {
      "id": "CVE-2026-44495",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:7e521628-164d-57bc-b801-10963a19dac1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.21.1 of axios."
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:3152f80a-a92c-5bc4-a491-25211f0e1ad4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 0.21.1 of axios, and is fixed in 0.21.1-tuxcare.2."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:3c727c1f-0f25-5202-be3f-201f71b83880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.21.1 of axios."
      }
    },
    {
      "id": "GHSA-f2r5-pqh9-r8f8",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:f071c33b-63f3-58e4-b68a-0575058a95b9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-f2r5-pqh9-r8f8 is a false positive for axios 0.21.1."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.21.1"
        }
      ],
      "bom-ref": "urn:uuid:b8f29d89-0bd0-561a-931b-182e19c429a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.21.1 of axios."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.21.1"
    }
  ]
}