{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a761f5e1-b625-550c-acaa-7d058b219630",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@1.7.9-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/axios@1.7.9-tuxcare.2",
      "version": "1.7.9-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a0d99960-5aec-5b47-b0b4-9f6fafacc0c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2025-58754",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e56c4311-ccf4-528d-a5a0-a42d8162ee74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9897943d-5c48-5dcd-9a0e-352e8e20021a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62718 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:066f6162-4305-5d04-8a03-6af1c9d3991b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25639 does not affect version 1.7.9-tuxcare.2 of axios. Version 1.7.9 is not vulnerable. Summary: The target repository (axios v1.7.9) is NOT vulnerable to CVE-2026-25639. The target uses Object.assign({}, config1, config2) for key iteration, which does not include __proto__ in Object.keys() results, preventing the DoS crash. The vulnerable code pattern was introduced later in v1.11.0 when the code was refactored to use the spread operator ({...config1, ...config2}). [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0ba6ed56-5de1-5d00-bbda-e1f035594cfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f7050ed4-d375-56cc-882e-c7cbc0341e6c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5b407fe8-4840-529e-ac85-95e3ea8ea016",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42034 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3dd61e50-8642-5fb8-87a9-a9f3ae94a347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42035 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a293f8e0-e5c2-500e-982c-bd056e046e30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42037",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:32c5eb0c-6832-555f-a6a9-5cef2d2a2b0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42037 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e5d65252-cc0d-51d6-b412-5fe292c7091f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42038 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:849cdfb8-540e-5f30-968e-074a02b238fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60df5cd5-909f-5795-99d6-e14f4d6b9151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42040 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c368df04-1043-50cf-b2f7-a6567076b9bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42041 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a2479b6f-532b-5fd4-818a-c8de1827852f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42042 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8d19bbb4-18aa-5deb-97bd-def195830304",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 1.7.9-tuxcare.2 of axios. Version 1.7.9 is not vulnerable. Summary: The target version (axios v1.7.9) is NOT vulnerable to CVE-2026-42043 because the vulnerable shouldBypassProxy feature does not exist in this version. The target uses the external 'proxy-from-env' package for proxy handling, whereas the vulnerability exists in axios's own shouldBypassProxy implementation that was only introduced in version 1.15.0. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42044",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1f4adc39-0117-51cf-9e24-bee3bcf3ce62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42044 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-42264",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e065f8d-6be7-5b5d-952e-c1fb3931a986",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42264 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5d7a198c-8466-569b-95b3-0c671d112623",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44486 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:20910886-43c1-5d86-b299-3c56f5bf43be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44487 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-44488",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:96ade030-15f4-5919-81ef-e1011ec5194f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44488 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ede4ec7f-4f8f-54bf-bcab-a408efa8ab37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fdf219f0-8163-5f54-a367-c3d4f01b155c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44492 affects version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-44494",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:29dd9e2e-08c8-5812-8746-a1843becb3c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44494 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-44495",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d17649c2-42c3-5887-8a98-d5a54a1ae72d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44495 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:11154dd1-93e0-5f15-a191-343e1effe367",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "CVE-2026-67312",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bad069f3-2716-5444-b0a9-b696bc2ebdd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67312 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-67313",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d8ea1885-5157-5958-9957-0538f7330547",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67313 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-67316",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76ec7eaf-3f93-5a54-a661-ef16b86b2bb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67316 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-67317",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:975149dc-c130-5a1e-8e97-76f1d9c61d2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67317 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-67319",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2f83c180-8ddf-55ff-a500-2a25ebe6e583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-67319 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.4."
      }
    },
    {
      "id": "GHSA-39j5-w47m-2gmv",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d99d04ab-0bb8-5df4-a08e-a2578f4bfb42",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-39j5-w47m-2gmv is a false positive for axios 1.7.9-tuxcare.2."
      }
    },
    {
      "id": "GHSA-42h9-826w-cgv3",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ea21350d-e6bf-5e02-ab97-2f89160e5905",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-42h9-826w-cgv3 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.3."
      }
    },
    {
      "id": "GHSA-4ww2-rjh2-xpv9",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7352eb61-4915-5472-be28-64d6df23e7db",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4ww2-rjh2-xpv9 is a false positive for axios 1.7.9-tuxcare.2."
      }
    },
    {
      "id": "GHSA-6hqm-hm2v-3p2p",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:191e29b1-caab-5b97-9a1b-bb95f5186b1c",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-6hqm-hm2v-3p2p is a false positive for axios 1.7.9-tuxcare.2."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d6a333cf-2295-5f30-ac9f-f3f10f075150",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "GHSA-9wx3-p993-35vp",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c6027bc9-32b8-579b-8c8c-f7695bc81f10",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-9wx3-p993-35vp is a false positive for axios 1.7.9-tuxcare.2."
      }
    },
    {
      "id": "GHSA-fq2j-3j99-rx65",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:457f9fc6-0b50-5bc3-9e21-0f717f6f0c82",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-fq2j-3j99-rx65 is a false positive for axios 1.7.9-tuxcare.2."
      }
    },
    {
      "id": "GHSA-jqh4-m9w3-8hp9",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:286c6eca-c0e5-5df6-b6b2-08152ba379a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jqh4-m9w3-8hp9 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.3."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6079dfdb-9595-52b7-851e-3be505600c21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx is fixed in version 1.7.9-tuxcare.2 of axios."
      }
    },
    {
      "id": "GHSA-pmv8-rq9r-6j72",
      "affects": [
        {
          "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d58fb4b1-58aa-5ac2-b188-7241d493b34b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pmv8-rq9r-6j72 affects version 1.7.9-tuxcare.2 of axios, and is fixed in 1.7.9-tuxcare.3."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@1.7.9-tuxcare.2"
    }
  ]
}