{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cb33c291-e661-5bf9-93f4-345d6b18f74c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "adm-zip",
      "purl": "pkg:npm/adm-zip@0.4.16",
      "type": "library",
      "bom-ref": "pkg:npm/adm-zip@0.4.16",
      "version": "0.4.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-102282",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:878f048f-eeb5-57f9-a245-a9c56260345c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-102282 does not affect version 0.4.16 of adm-zip. not_affected \u2014 Version 0.4.16 is not affected by CVE-2026-102282. The vulnerability requires the `keepOriginalPermission` feature and `fileAttr` getter, which were introduced in commit 2b2a1d7 (September 2021). This commit is not in 0.4.16's ancestry. The target always extracts files with default permission 0o666, completely ignoring zip entry permission bits. The attack chain from zip attributes to files wit...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-39244",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:4ad0a0b8-88ba-525c-beea-fb90c29ca3de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39244 affects version 0.4.16 of adm-zip, and is fixed in 0.4.16-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-77301",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:448a33de-cda5-55a9-bb7b-81a6cf4497c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-77301 affects version 0.4.16 of adm-zip, and is fixed in 0.4.16-tuxcare.1."
      }
    },
    {
      "id": "GHSA-8238-w5pm-2374",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:8abb3e56-3f17-5183-8a32-e452395fabb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8238-w5pm-2374 affects version 0.4.16 of adm-zip."
      }
    },
    {
      "id": "GHSA-c6fg-446q-cg94",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:514f049d-068d-5ff8-8611-4df58fe01a4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c6fg-446q-cg94 affects version 0.4.16 of adm-zip."
      }
    },
    {
      "id": "GHSA-p634-w6r4-rjp2",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:974ada54-69fd-5cb4-aeaf-fec83e9d4f93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-p634-w6r4-rjp2 affects version 0.4.16 of adm-zip."
      }
    },
    {
      "id": "GHSA-rcw4-f5rp-g42v",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.16"
        }
      ],
      "bom-ref": "urn:uuid:c61b64cb-3b73-5983-b4e7-02b0d83c6a05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rcw4-f5rp-g42v affects version 0.4.16 of adm-zip."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/adm-zip@0.4.16"
    }
  ]
}