{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:37168437-da8e-52a4-b07a-4c1bc076aa04",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@1.6.8",
      "type": "library",
      "bom-ref": "pkg:npm/axios@1.6.8",
      "version": "1.6.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-39338",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:a0b2ea29-7735-5178-bccc-1738bc9d0ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39338 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:03d5cc8d-38e5-5694-b29c-acd7fb552c77",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-27152 does not affect version 1.6.8 of axios. CVE-2025-27152 fix already exists in commit 22c2e77ccde46e0a3c0d1513b682eba8dfb41d75",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-58754",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:e8033ef6-d59c-5ce7-bfca-97efa49f3239",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-58754 does not affect version 1.6.8 of axios. CVE-2025-58754 fix already exists in commit fe89d8c609e567fa731f7677ab065742330f25ea",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:1512842b-c17a-5e78-8934-31187d4d768a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 1.6.8 of axios. CVE-2025-62718 fix already exists in commit dd333bdabf51d856d0d14fe7bd9d50ac817e4aa2",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:a4f848d9-3dc0-54f5-bdcf-a1cbb0d1266b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.6.8 of axios. CVE-2026-25639 fix already exists in commit f4e3c49872deb794ae9a7bb71a8345ea2ec4b6eb",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:441b3cac-639d-50bd-a199-fe913b44756f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40175 does not affect version 1.6.8 of axios. CVE-2026-40175 fix already exists in commit e3c915c5421c511d667ffeace65d8d65829e19e8",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:ebb505e3-bda5-5c24-92ea-36706bdb21f9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42033 does not affect version 1.6.8 of axios. CVE-2026-42033 fix already exists in commit 9c513d377d64d936e51eb33b901bb6a26258abd8",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:851d1024-0436-5b99-a7cf-01c2994c3783",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 1.6.8 of axios. CVE-2026-42034 fix already exists in commit cd256b069536974eeec07e8047ceeb87986d19bc",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:0afc77a2-a512-5222-8c49-5217e25da3c5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 1.6.8 of axios. CVE-2026-42035 fix already exists in commit b9e4e1b49f5f62215e46c059f343b2e9ccb81c39",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:3b9d9629-4c8b-5e35-8df8-84da84fbf7b0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42036 does not affect version 1.6.8 of axios. CVE-2026-42036 fix already exists in commit db7082ebbf0cf245e8d001407b789a154606afac",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42037",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:05a33b18-484d-57ef-970d-4e69cf2a315d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42037 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:15c69b28-b1ec-54df-90b3-f11513ec6cb9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 1.6.8 of axios. CVE-2026-42038 fix already exists in commit 38fbaef2676858fc97ea981cf9e2fabf343e60a4",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:e0c8ff52-bc02-5ea3-8b8b-f5ab5694e761",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42039 does not affect version 1.6.8 of axios. CVE-2026-42039 fix already exists in commit da36cba07a133fa5f833556303db0e3e5ce3dc87",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:e2121eeb-641c-58df-a38d-8c8023cbeca0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:ace0edbe-6084-5fd0-90dc-d2723cac88d0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 1.6.8 of axios. CVE-2026-42041 fix already exists in commit 935b8c002f9b50ff36d4f0ed3b6be5fc855a0b6e",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:75818e7c-b60f-5883-ae6d-4abf50ffa5b5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 1.6.8 of axios. CVE-2026-42042 fix already exists in commit be54ef4e740e14b267e765f8e42ff9104d78bc8b",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:56d787b0-9530-5005-92b9-447e214b564f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.6.8 of axios. CVE-2026-42043 fix already exists in commit 2a6288f317a7bfc46a41088a3809a22e8193340a",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42044",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:32fde97d-6f19-5ac9-a377-a28538591f35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42044 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-42264",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:1e3d4bc7-2232-5072-ad5f-fa3dedf0dc68",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42264 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:cb1541b9-4c7b-51c9-bf7b-d4f6f535446e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:16e6b3f6-4762-5ce3-8ead-ff76a52979c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:82edc849-cc55-5f74-8dd1-a933d0209265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:2488681f-b30f-50af-9482-e3e3314805c1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 1.6.8 of axios. not_affected \u2014 axios v1.6.8 is not affected by CVE-2026-44492. The vulnerable code (lib/helpers/shouldBypassProxy.js) was introduced in v1.15.0, and v1.6.8 predates this entirely. The target uses a different architecture (proxy-from-env only) that is outside the scope of this CVE.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44494",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:990b5916-1275-5643-9a25-e0bacd2d2840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44494 affects version 1.6.8 of axios."
      }
    },
    {
      "id": "CVE-2026-44495",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:f685b06c-3637-540f-9a3a-632a18108579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.6.8 of axios."
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:cbaac2ab-b89e-5f1b-85ab-efe111132343",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.2."
      }
    },
    {
      "id": "GHSA-42h9-826w-cgv3",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:792cbb2a-dca1-5743-9c8f-d0ce8dc6f23b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.6.8 of axios."
      }
    },
    {
      "id": "GHSA-4ww2-rjh2-xpv9",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:4bcc8731-d244-562e-bee2-b0bbbe0c3272",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4ww2-rjh2-xpv9 is a false positive for axios 1.6.8."
      }
    },
    {
      "id": "GHSA-6hqm-hm2v-3p2p",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:7cce491e-3fdd-502c-a7b1-41cff0c4b0ee",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6hqm-hm2v-3p2p is a false positive for axios 1.6.8."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:e09f095c-eecf-5709-a061-4741fbf9146f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.6.8 of axios."
      }
    },
    {
      "id": "GHSA-9wx3-p993-35vp",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:885b3848-8f6a-58e3-9f12-c130e25c2198",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-9wx3-p993-35vp is a false positive for axios 1.6.8."
      }
    },
    {
      "id": "GHSA-fq2j-3j99-rx65",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:1dd597ed-ec59-57ab-87ce-1a0f53f91b59",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fq2j-3j99-rx65 is a false positive for axios 1.6.8."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:4fa4adbf-81dd-5f1a-995a-c6dc8cfa073a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 1.6.8 of axios, and is fixed in 1.6.8-tuxcare.3."
      }
    },
    {
      "id": "GHSA-pmv8-rq9r-6j72",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.6.8"
        }
      ],
      "bom-ref": "urn:uuid:f6096204-07bd-59fa-ad2a-3509d6e61f07",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.6.8 of axios."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.6.8"
    }
  ]
}