{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cbaee2d9-04ca-541a-b914-d8f0b8fe1f4b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dcodeio_dcodeio_protobuf.js",
      "purl": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2",
      "version": "6.10.2-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-25878",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:40ec6ab9-c4dd-5079-ba75-5d22022e9afb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25878 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2023-36665",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d2153b46-01ab-5d8a-9952-d564a185b502",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36665 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-41242",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4851cdbd-f2e6-5dd4-9cb2-b95054a68f62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44288",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d6041d8-0899-5c35-91c9-8a8a6ef8bdea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44288 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44289",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cd891beb-b4c1-5285-8007-23f61bc012e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44290",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e54878a4-71c0-5cba-9ced-a2c88e628e28",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js. CVE-2026-44290 fix already exists in commit f87c65fb1bedc7be0ee2504542878b86ee943218",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44291",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:36bbc087-e222-562a-a12b-3b83798f4e4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44291 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44292",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f8e07f81-6697-57c6-ac1a-2469ab04c095",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44292 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44293",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:df9cd720-0769-5f89-8977-702033c94f3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44293 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44294",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f13db2ce-131a-5e75-bf4d-8cfbb9e811ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44294 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-45740",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e6cb612-46e5-5a28-a499-b4b2f3e5de5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-48712",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:56fb003c-f6ed-5180-b2ba-8c6ef38e6a2d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-54269",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fafacddd-b851-512d-8a46-0766ce55b622",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-54270",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8f295248-6e87-5766-b36f-213d55c2a6c2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 Target version 6.10.2 is not affected by CVE-2026-54270. The vulnerability concerns excessive memory retention from unknown field preservation, a feature introduced in protobufjs 8.2.0. Version 6.10.2 does not implement unknown field preservation; unknown fields are simply skipped during decode without storing them in memory.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59876",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b9a61750-e0a2-59be-a1f8-29050adbb521",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 CVE-2026-59876 specifically affects the optional Text Format extension (ext/textformat.js) which does not exist in protobufjs version 6.10.2. This extension was introduced as a new feature in version 8.x. Without the Text Format extension, the attack vector described in the CVE cannot be exploited.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59877",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:506ee98b-9942-5ca9-b298-d806ef46b0d8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.10.2-tuxcare.2 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 Version 6.10.2 is not affected by CVE-2026-59877. The vulnerable code pattern (a while loop advancing through tokens looking for '=' without EOF checking) does not exist in this version. Version 6.10.2 uses a different architecture with skip('=') that properly handles EOF by throwing an error.",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.2"
    }
  ]
}