{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f9b6b562-991a-52fe-8c41-0ae1817ec7e1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@1.7.7",
      "type": "library",
      "bom-ref": "pkg:npm/axios@1.7.7",
      "version": "1.7.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:7006fd87-3e50-5662-a6eb-016c41cef287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27152 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2025-58754",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:77276684-870f-5458-9940-7c56e94f5615",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58754 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.1."
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:a9f43f6f-eaa8-55c4-8596-1b2c17d37a19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62718 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:5a65fe3d-41ea-5e17-ae8d-d33a1455de29",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25639 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:55535140-d1ae-5139-b74f-91234dfc5d77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40175 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:bcf24f22-2d09-58e7-b573-7fe5ebee3aa1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42033 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:c7ef6c86-a8b1-5381-a872-3e41a61fa40f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42034 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:41c40631-f027-55a6-9de4-41a77b40e9ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42035 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:1a01dabb-cfdc-53fe-bc2a-b8ca05f69556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42036 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42037",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:314d93d7-b628-5bd6-9e86-3439d95b767e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42037 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:7897130a-557b-5022-adf5-4e13ffbf233b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42038 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:1e5b0c89-bf7f-5f62-a446-c0d3993f44bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42039 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:16efec25-5123-5b01-a14d-037edd3be031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42040 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:f3a9ecaa-d3e8-5e86-9401-4c38d10d8535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42041 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:9fe24a3c-1cbd-5524-8fe4-93634152c69c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42042 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:a4b82e23-a053-5b00-a618-91078b184aa7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42043 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42044",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:ca2e08f4-2ed0-513e-b07a-428ebf751ff0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42044 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-42264",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:6bd3cd3e-dfcd-54fd-96ce-02d2ace478d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42264 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:ac69224a-3747-5901-9b2b-432f78c0f2b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:9cd4fb5c-4a52-57d0-bf0c-5f40ceae5c64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44487 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-44488",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:97d30e4e-2c8d-5bb4-aef8-dde11e9050a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44488 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:d54a2f69-37a7-5732-89a5-7d0023bbb7d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44490 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:bbac6a12-731b-5e61-925f-7f9376cdd05a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 1.7.7 of axios."
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:5e9f7c08-52e2-5a55-a091-9f7f979f9145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44496 affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.4."
      }
    },
    {
      "id": "GHSA-39j5-w47m-2gmv",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:677a1cbd-6b44-546d-9285-bccaa60f0fa5",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-39j5-w47m-2gmv is a false positive for axios 1.7.7."
      }
    },
    {
      "id": "GHSA-42h9-826w-cgv3",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:0fc382db-182a-5b8b-9bb0-c9efdb0e1056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.7.7 of axios."
      }
    },
    {
      "id": "GHSA-4ww2-rjh2-xpv9",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:4f3df83d-30da-533d-bd3c-fe6e54fadb3f",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4ww2-rjh2-xpv9 is a false positive for axios 1.7.7."
      }
    },
    {
      "id": "GHSA-6hqm-hm2v-3p2p",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:dd9fdf1b-da3f-534e-b402-53c380b9651b",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6hqm-hm2v-3p2p is a false positive for axios 1.7.7."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:e75a9945-95b2-5fa6-a68f-92b922e44b59",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 1.7.7 of axios."
      }
    },
    {
      "id": "GHSA-9wx3-p993-35vp",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:dd26d690-c78e-5056-8205-1ecd4d49396c",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-9wx3-p993-35vp is a false positive for axios 1.7.7."
      }
    },
    {
      "id": "GHSA-fq2j-3j99-rx65",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:7d168f7f-24ca-5c4d-9577-b790e72ed9ac",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fq2j-3j99-rx65 is a false positive for axios 1.7.7."
      }
    },
    {
      "id": "GHSA-jqh4-m9w3-8hp9",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:ac3f1dd5-d69c-5776-b6f8-cc95dce1b819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jqh4-m9w3-8hp9 affects version 1.7.7 of axios."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:62bf6112-3f56-5248-96b4-7b544880d9c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 1.7.7 of axios, and is fixed in 1.7.7-tuxcare.5."
      }
    },
    {
      "id": "GHSA-pmv8-rq9r-6j72",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.7"
        }
      ],
      "bom-ref": "urn:uuid:4ea17b79-aa8e-52ec-8d33-0a16aa63e654",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.7.7 of axios."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.7.7"
    }
  ]
}