{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:39234c8f-21a9-5229-a574-e791d0262cb7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@0.24.0",
      "type": "library",
      "bom-ref": "pkg:npm/axios@0.24.0",
      "version": "0.24.0",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-45857",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:6c3e81bb-2371-59e9-aa7e-0b5aca1194d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-45857 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2024-39338",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:1cfd0152-6684-57ef-bd06-73610c8fca1b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-39338 does not affect version 0.24.0 of axios. Target version 0.24.0 is NOT affected by CVE-2024-39338. The vulnerability exists in axios 1.7.2+ which uses the WHATWG URL constructor (new URL()) that resolves protocol-relative URLs. The target uses the legacy Node.js url.parse() API which does not treat '//attacker.com' as protocol-relative, breaking the SSRF attack chain. Testing confirms url.parse('//attacker.com:8888') returns hostname=null (treated as pathname), causing HTTP requests to default to localhost instead of the attacker's server.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:bc08bc3b-0141-59e0-af54-4a1ce0f89def",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27152 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:faa29c08-4d8a-5d00-8996-9fe43fd46168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:88edd5bf-9fcc-5985-8bf2-9a856a81cd03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25639 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:230bcf28-a0ea-5dc7-a99a-93f6d647bc12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:821c939b-e576-5fb6-bcfa-966024c92651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:6365cd72-54ba-50fd-af50-02fd5218c613",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:5a2917bd-7095-5cb7-bb65-cd8de6de81f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:c314e05b-a877-5490-87e6-20bdf2432972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:2e649e7b-380b-53ce-84c6-94b0b9178511",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:85def9fe-3954-5798-9b94-9c8844c3fe0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42039 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:e568c448-2e2b-5885-a4be-92aa40224986",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:2d7f47f0-9f4c-5802-8fe6-93015f4af113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:bd0de389-9292-5cd1-9133-2dc612f026e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:42d2f0bf-5465-5c02-93cb-231178157a4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:74ae9de2-e858-5beb-83f1-2f0925416dbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:d933847e-7a04-569c-b9bb-b13fc1c42b2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:a64d8129-7a9d-54d0-9715-4e598db32d84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:b99c2caa-1400-54aa-a34e-db285fe3b61e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 0.24.0 of axios."
      }
    },
    {
      "id": "CVE-2026-44495",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:3e2084a1-21d3-515a-8c9b-70a7ef843ce2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 0.24.0 of axios."
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:35aa9ef6-97df-5601-bdd7-16771458c375",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 0.24.0 of axios, and is fixed in 0.24.0-tuxcare.2."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:330cc0ab-0530-5099-9829-447997d78451",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.24.0 of axios."
      }
    },
    {
      "id": "GHSA-f2r5-pqh9-r8f8",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:3daedddc-8b21-508d-a6ea-f76b40e4c16f",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-f2r5-pqh9-r8f8 is a false positive for axios 0.24.0."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.24.0"
        }
      ],
      "bom-ref": "urn:uuid:8a0a2dc5-90e1-569f-a949-25c286bb81f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.24.0 of axios."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.24.0"
    }
  ]
}