{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:924dcd44-f69b-5c81-8bbc-138b751cf2a3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dcodeio_dcodeio_protobuf.js",
      "purl": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1",
      "version": "6.10.2-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-25878",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8cb7cbde-2e8e-58b6-bc5a-7ab8eb7d6234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25878 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2023-36665",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4fd60b14-f979-50b3-aff1-678b3c07dfd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36665 is fixed in version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-41242",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8e9ebd23-6149-508a-a139-2a732841c162",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44288",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b4d1753e-4605-5cb1-81c8-3d7efecb3e36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44288 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44289",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:535e4d53-ab09-5b8d-86d6-bcfee0a213ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44289 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44290",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aede38b8-be93-5708-a595-be8b8e195443",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js. CVE-2026-44290 fix already exists in commit f87c65fb1bedc7be0ee2504542878b86ee943218",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44291",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8b9c0ebe-46b8-5f91-955f-397efcd6c2cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44291 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44292",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:79c9e478-1bde-5830-afdf-4b009885ce7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44292 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44293",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b22aeb1f-0e92-5b39-8817-4bc86c63cefd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44293 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-44294",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cebdd00f-8797-5305-943c-6d44201ee050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44294 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-45740",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80913439-e5b6-5e01-8755-54ed06bb99f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-48712",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4a2a4f0-9e21-5874-8d9f-10c597df73a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-54269",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b6141606-1364-52f8-9c4e-8c54b6beacab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-54270",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:380d007f-a56e-555f-8741-12ecdd0d0dac",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 Target version 6.10.2 is not affected by CVE-2026-54270. The vulnerability concerns excessive memory retention from unknown field preservation, a feature introduced in protobufjs 8.2.0. Version 6.10.2 does not implement unknown field preservation; unknown fields are simply skipped during decode without storing them in memory.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59876",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:31947c77-7b42-5041-849f-0f6a712a12b6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 CVE-2026-59876 specifically affects the optional Text Format extension (ext/textformat.js) which does not exist in protobufjs version 6.10.2. This extension was introduced as a new feature in version 8.x. Without the Text Format extension, the attack vector described in the CVE cannot be exploited.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59877",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec0a5edd-d478-5658-9e07-d66ffc38fa45",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.10.2-tuxcare.1 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 Version 6.10.2 is not affected by CVE-2026-59877. The vulnerable code pattern (a while loop advancing through tokens looking for '=' without EOF checking) does not exist in this version. Version 6.10.2 uses a different architecture with skip('=') that properly handles EOF by throwing an error.",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.1"
    }
  ]
}