{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7cb6e192-bf2c-58ea-8c49-edd146d1251f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1",
      "type": "library",
      "name": "@astrojs/upgrade",
      "version": "4.16.19-tuxcare.1",
      "purl": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ffa94f5f-d95d-57a7-9d53-186a430403cc",
      "id": "AIKIDO-2025-10879",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10879 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2bdcf3-7e97-5fac-992f-3a8e116b00cc",
      "id": "CVE-2025-55303",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55303 affects version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f50f317f-d7be-5176-bd11-5c2bfced5e32",
      "id": "CVE-2025-61925",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61925 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53a2b231-b03b-5a57-b565-10050622c5dc",
      "id": "CVE-2025-64525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64525 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e49456b-9410-5a67-991c-8f027d493bcf",
      "id": "CVE-2025-64757",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64757 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af99365d-8bcc-59dd-9c6c-2af9eda87801",
      "id": "CVE-2025-64764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64764 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea29036-e677-5c7b-82d8-792af20c6c3c",
      "id": "CVE-2025-64765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64765 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc2b9b8-9d10-57d1-8147-957c8c41da68",
      "id": "CVE-2025-65019",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-65019 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc827b14-b6dc-5520-a493-ec2f85ddf01b",
      "id": "CVE-2025-66202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66202 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30cde853-0d0a-58e5-a7c9-707d4bcd45e5",
      "id": "CVE-2026-32887",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-32887 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 CVE-2026-32887 concerns the Effect framework (TypeScript framework with RpcServer/HttpApp APIs), but the target repository is Astro (a website build tool). These are completely different projects with no dependency relationship. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb8121ba-223c-5e52-a5d2-a646cee203a4",
      "id": "CVE-2026-33128",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33128 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 CVE-2026-33128 concerns H3 framework, but the target repository is Astro framework. This is a wrong-project match with no code relationship between the two projects."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aaa7cc7-6d98-5327-ab28-4bcbb37d29af",
      "id": "CVE-2026-33131",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33131 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 CVE-2026-33131 concerns the H3 framework, but the target repository is Astro (version 4.16.19-tuxcare.1), a completely different web framework. H3 is not used as a dependency, not vendored in the source tree, and the affected components (NodeRequestUrl, FastURL) do not exist in this codebase. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcb31d2-2ac2-5e85-a115-07cc121c6a93",
      "id": "CVE-2026-33490",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33490 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 CVE-2026-33490 concerns H3 (a minimal HTTP framework), but the target repository is Astro (a website build tool). H3 is not present in this repository - no vendored code, no dependency, no imports. The only 'h3' references found are HTML heading components (<h3> tags), unrelated to the H3 framework."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba4de63-c110-5783-a891-f4b0e23b028e",
      "id": "CVE-2026-33769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33769 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa08d9b-b92e-58f1-9764-0106e76e49be",
      "id": "CVE-2026-41067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41067 is fixed in version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:513362eb-4a0c-5a7c-bd4f-b44a6533e211",
      "id": "CVE-2026-45028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45028 affects version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea5e7c8-d2ca-583a-aeb9-068d2c561dda",
      "id": "CVE-2026-50146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50146 affects version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f9a1c51-6311-5092-8b59-cf55283b5ba0",
      "id": "CVE-2026-54298",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54298 affects version 4.16.19-tuxcare.1 of @astrojs/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c196df3-6fdb-557d-9216-6251b6a81cb1",
      "id": "CVE-2026-54299",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54299 does not affect version 4.16.19-tuxcare.1 of @astrojs/upgrade. already_fixed \u2014 The target repository has already fixed this vulnerability via CVE-2026-25545 / AIKIDO-2025-10879 (May 7, 2026), which addresses the identical SSRF issue. The fix removes the prerendered error page fetching feature entirely, replacing it with direct SSR rendering. This is a more aggressive mitigation than the upstream's host validation approach."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88e3bc0c-1b68-5fd4-b35e-3e4c9b7dec63",
      "id": "GHSA-4hxc-9384-m385",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-4hxc-9384-m385 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 Wrong-project match: CVE GHSA-4hxc-9384-m385 concerns the h3 package's EventStream SSE injection vulnerability, but the target repository is Astro (version 4.16.19-tuxcare.1), a completely different web framework. The h3 package and its affected component are entirely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aba57259-e7ea-545e-adc6-4f0d0f67499a",
      "id": "GHSA-q5pr-72pq-83v3",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-q5pr-72pq-83v3 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 This is a wrong-project match. The CVE GHSA-q5pr-72pq-83v3 concerns h3's chunked cookie handling vulnerability, but this repository is Astro (a website build tool), which does not use h3 or contain any h3 code."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e0bf0db-edfc-567a-85d3-d53d71be17c6",
      "id": "GHSA-wr4h-v87w-p3r7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-wr4h-v87w-p3r7 is a false positive for @astrojs/upgrade 4.16.19-tuxcare.1. false_positive \u2014 This advisory (GHSA-wr4h-v87w-p3r7) concerns the h3 library's serveStatic() function, but the target repository is Astro, a completely different web framework. The h3 library is not present in this repository in any form - not as the project itself, not as a vendored/bundled dependency, and not as a declared dependency."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40astrojs/upgrade@4.16.19-tuxcare.1"
    }
  ]
}