{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ddf66b46-c350-50a8-97d8-ce6c34cdc110",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "nodemailer",
      "purl": "pkg:npm/nodemailer@6.10.1",
      "type": "library",
      "bom-ref": "pkg:npm/nodemailer@6.10.1",
      "version": "6.10.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-13033",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:9e689913-40fb-5b0d-9070-68b8205c8f35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13033 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.1."
      }
    },
    {
      "id": "CVE-2025-14874",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:db2f2bee-cb49-5a1a-b377-fa1abd2bb302",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14874 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-82659",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:a1fc0d0c-0c99-57f3-96ec-9dc05acef533",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-82659 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-82660",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:2a8b835b-c666-5253-9a66-bb31aa4d6a86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-82660 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-82661",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:d4cbcfcc-6250-5385-ba3b-e019aa5104f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-82661 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-82662",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:13f1d94a-454d-5377-a38e-6ee957d218b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-82662 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-82853",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:a690619e-7d0d-52e6-a226-e0a115d7fb0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-82853 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-82854",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:f0edcd47-efd1-578d-a06c-40537e5cd133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-82854 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.9."
      }
    },
    {
      "id": "GHSA-268h-hp4c-crq3",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:59829a33-eb86-5674-8616-429f335894b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-268h-hp4c-crq3 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.8."
      }
    },
    {
      "id": "GHSA-2x7j-588g-ccc2",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:4a40aa1b-3447-5fe1-a315-5b2ada07992e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2x7j-588g-ccc2 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.8."
      }
    },
    {
      "id": "GHSA-46j5-6fg5-4gv3",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:4f9aacf2-ce8c-504c-9562-cde442c9742d",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-46j5-6fg5-4gv3 is a false positive for nodemailer 6.10.1."
      }
    },
    {
      "id": "GHSA-8m3c-c648-2xjj",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:bed59c1a-7c48-5b9e-8803-8082dc35e5b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8m3c-c648-2xjj affects version 6.10.1 of nodemailer."
      }
    },
    {
      "id": "GHSA-c7w3-x93f-qmm8",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:9535b6dd-af86-5469-85fb-3b81a90b8a0c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c7w3-x93f-qmm8 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.6."
      }
    },
    {
      "id": "GHSA-cc9r-2j5m-2m83",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:32155da4-9994-5937-bd79-46e6d7c0e121",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cc9r-2j5m-2m83 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.8."
      }
    },
    {
      "id": "GHSA-h3hj-cmcx-xc66",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:0fa5393a-203e-5162-9bc1-a9670273b550",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-h3hj-cmcx-xc66 is a false positive for nodemailer 6.10.1."
      }
    },
    {
      "id": "GHSA-jj37-3377-m6vv",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:d7130a17-1877-5715-a073-e4e3b99e8bdb",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-jj37-3377-m6vv is a false positive for nodemailer 6.10.1."
      }
    },
    {
      "id": "GHSA-mm7p-fcc7-pg87",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:a6085583-fe93-5b80-ab57-478e4591a731",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mm7p-fcc7-pg87 does not affect version 6.10.1 of nodemailer. already_fixed \u2014 The target repository (nodemailer 6.10.1-tuxcare.3) already contains the complete security fix for CVE-2025-13033/GHSA-mm7p-fcc7-pg87. The fix was backported by TuxCare on December 9, 2025 via commit 189d7aa. The vulnerability involved incorrect parsing of quoted local-parts containing @ symbols, which could cause email misrouting to attacker-controlled domains. The fix adds quote state trackin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-p6gq-j5cr-w38f",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:168322f6-a315-5b98-b3de-a4765575e370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-p6gq-j5cr-w38f affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.5."
      }
    },
    {
      "id": "GHSA-r7g4-qg5f-qqm2",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:764acbe3-0dda-5e2a-9401-049840f5cb41",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r7g4-qg5f-qqm2 affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.6."
      }
    },
    {
      "id": "GHSA-vvjj-xcjg-gr5g",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:e82f0ef8-d177-5165-96bf-5532227786f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-vvjj-xcjg-gr5g affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.4."
      }
    },
    {
      "id": "GHSA-wmmp-3585-3rmp",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:25215de7-d93a-541e-a60b-2121f9d30f1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wmmp-3585-3rmp affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.8."
      }
    },
    {
      "id": "GHSA-wqvq-jvpq-h66f",
      "affects": [
        {
          "ref": "pkg:npm/nodemailer@6.10.1"
        }
      ],
      "bom-ref": "urn:uuid:7211467c-95ea-5d32-8152-91ed972c78ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wqvq-jvpq-h66f affects version 6.10.1 of nodemailer, and is fixed in 6.10.1-tuxcare.5."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/nodemailer@6.10.1"
    }
  ]
}