{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:51747dd1-2cac-532f-916a-f051bce09c13",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "adm-zip",
      "purl": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2",
      "version": "0.4.4-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2018-1002204",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:18d24688-153c-577a-8e2a-65016087756c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1002204 is fixed in version 0.4.4-tuxcare.2 of adm-zip."
      }
    },
    {
      "id": "CVE-2023-0842",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:58208cb2-7dde-53a6-8dc7-06efe795eda7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-0842 is a false positive for adm-zip 0.4.4-tuxcare.2. false_positive \u2014 CVE-2023-0842 is a wrong-project match. The advisory concerns xml2js (an XML parsing library), while the target repository is adm-zip version 0.4.4-tuxcare.1 (a ZIP compression library). These are completely different products with no code relationship."
      }
    },
    {
      "id": "CVE-2026-102282",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9ec80ad5-87cd-5987-ac74-7563ad2a3e55",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-102282 does not affect version 0.4.4-tuxcare.2 of adm-zip. not_affected \u2014 Version 0.4.4 predates the vulnerable feature entirely. The `keepOriginalPermission` parameter and `fileAttr` getter that enable the vulnerability were introduced in version 0.5.16+. In version 0.4.4, extraction methods (`extractAllTo`, `extractEntryTo`) never read or apply Unix permission bits from zip entries\u2014all extracted files receive default permissions (0o666). While external attributes a...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-39244",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3139c526-d0a3-5fe7-8535-c0381a20a5f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39244 is fixed in version 0.4.4-tuxcare.2 of adm-zip."
      }
    },
    {
      "id": "CVE-2026-77301",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e834ff51-184e-515a-9af2-6ae8848a82e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-77301 is fixed in version 0.4.4-tuxcare.2 of adm-zip."
      }
    },
    {
      "id": "GHSA-8238-w5pm-2374",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8b42b6a6-a8e3-5766-984d-5e8587351f63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8238-w5pm-2374 affects version 0.4.4-tuxcare.2 of adm-zip."
      }
    },
    {
      "id": "GHSA-c6fg-446q-cg94",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b499808c-5d73-5cd0-b735-c64a3eb95b23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c6fg-446q-cg94 affects version 0.4.4-tuxcare.2 of adm-zip."
      }
    },
    {
      "id": "GHSA-p634-w6r4-rjp2",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:76f666ec-82a6-5bec-b954-34e408df3c3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-p634-w6r4-rjp2 affects version 0.4.4-tuxcare.2 of adm-zip."
      }
    },
    {
      "id": "GHSA-rcw4-f5rp-g42v",
      "affects": [
        {
          "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:99c72c6c-e7fb-5c0c-9ced-dd73076cf003",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rcw4-f5rp-g42v affects version 0.4.4-tuxcare.2 of adm-zip."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/adm-zip@0.4.4-tuxcare.2"
    }
  ]
}