{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1bae5e59-986d-5f59-94b2-dfefde9204a8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "dcodeio_dcodeio_protobuf.js",
      "purl": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3",
      "version": "6.10.2-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-25878",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dd9053a9-257c-51b8-af76-ec317b76441a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25878 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2023-36665",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:426de18d-5a0a-527a-883c-0101962fc888",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36665 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-41242",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:159624a8-a03f-5ff7-8d46-bec8da535031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41242 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44288",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fdd36996-1a7a-5491-8849-0ae87422b232",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44288 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44289",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5626a7f8-cec0-5503-bfdf-1187d6912804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44289 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44290",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b99d7db6-0e0a-57d8-a60a-52fa9e1a6ed5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44290 does not affect version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js. CVE-2026-44290 fix already exists in commit f87c65fb1bedc7be0ee2504542878b86ee943218",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44291",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a883e602-a97c-5f59-9e06-46fb3c0e8242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44291 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44292",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c6eda4c4-582d-5db3-8203-894391d34d79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44292 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44293",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f7a5fa67-c924-591c-891c-aa6a7c5f2cc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44293 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-44294",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9a2ef056-cec7-5df6-91ef-9b9b460eb3cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44294 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-45740",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4e3b32dc-cc80-5d4c-a87f-7f02975413d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45740 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-48712",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cf08b436-b9a8-5c32-bcf3-b68cb6c7f70b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48712 is fixed in version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js."
      }
    },
    {
      "id": "CVE-2026-54269",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:daa73ce1-2358-56fc-91de-6c90c74fcbcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54269 affects version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js, and is fixed in 6.10.2-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-54270",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fb5fca27-486e-5f65-8d34-52e2fa9cc481",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54270 does not affect version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 Target version 6.10.2 is not affected by CVE-2026-54270. The vulnerability concerns excessive memory retention from unknown field preservation, a feature introduced in protobufjs 8.2.0. Version 6.10.2 does not implement unknown field preservation; unknown fields are simply skipped during decode without storing them in memory.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59876",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:67b4358a-a3eb-5266-ba89-5b54b1edc64f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59876 does not affect version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 CVE-2026-59876 specifically affects the optional Text Format extension (ext/textformat.js) which does not exist in protobufjs version 6.10.2. This extension was introduced as a new feature in version 8.x. Without the Text Format extension, the attack vector described in the CVE cannot be exploited.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59877",
      "affects": [
        {
          "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:49440e5d-ef3e-54c4-a4d7-45baa7fb9b73",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59877 does not affect version 6.10.2-tuxcare.3 of dcodeio_dcodeio_protobuf.js. not_affected \u2014 Version 6.10.2 is not affected by CVE-2026-59877. The vulnerable code pattern (a while loop advancing through tokens looking for '=' without EOF checking) does not exist in this version. Version 6.10.2 uses a different architecture with skip('=') that properly handles EOF by throwing an error.",
        "justification": "code_not_present"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/dcodeio_dcodeio_protobuf.js@6.10.2-tuxcare.3"
    }
  ]
}