{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5523fd7f-0b63-51eb-9674-7bf5ac9c45f9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "mysql2",
      "purl": "pkg:npm/mysql2@2.3.3-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/mysql2@2.3.3-tuxcare.4",
      "version": "2.3.3-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "AIKIDO-2026-10225",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9bc45a23-6b77-5b18-93c0-ace66c727417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10225 is fixed in version 2.3.3-tuxcare.4 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21507",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:df18af40-5fb4-5827-a4ab-e176b1513ccc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21507 is fixed in version 2.3.3-tuxcare.4 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21508",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:aff33981-d639-5c6f-8cd7-986faa762661",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21508 is fixed in version 2.3.3-tuxcare.4 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21509",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:92c027ee-33bb-5d53-843c-703c8bf7981d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21509 affects version 2.3.3-tuxcare.4 of mysql2, and is fixed in 2.3.3-tuxcare.5."
      }
    },
    {
      "id": "CVE-2024-21511",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e7820533-0090-5f13-92da-3aa356d8fdfa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21511 is fixed in version 2.3.3-tuxcare.4 of mysql2."
      }
    },
    {
      "id": "CVE-2024-21512",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:890d1895-25d8-5639-beea-9f91ab17dba1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21512 is fixed in version 2.3.3-tuxcare.4 of mysql2."
      }
    },
    {
      "id": "GHSA-3f6p-5ww8-9rcr",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:73af4d38-8da0-506d-9091-bd0447cf030b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-3f6p-5ww8-9rcr does not affect version 2.3.3-tuxcare.4 of mysql2. not_affected \u2014 Version 2.3.3-tuxcare.6 is NOT AFFECTED by GHSA-3f6p-5ww8-9rcr. The vulnerable mysql_clear_password authentication plugin does not exist in this version. The plugin was only introduced in v3.0.0-rc.1 (March 2022), well after v2.3.3 was released (November 2021). When a rogue server requests the mysql_clear_password plugin via AuthSwitchRequest, the library rejects it with error \"Server requests ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-rgwj-5xj2-c3m3",
      "affects": [
        {
          "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:08bd407e-745a-5dc4-ab27-98599262c0b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rgwj-5xj2-c3m3 affects version 2.3.3-tuxcare.4 of mysql2, and is fixed in 2.3.3-tuxcare.6."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/mysql2@2.3.3-tuxcare.4"
    }
  ]
}