{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:59648758-ccbb-5735-8738-8066ef6460d5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@0.18.1-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/axios@0.18.1-tuxcare.6",
      "version": "0.18.1-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-28168",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1bd79572-687a-5c77-9649-fb0846c2cc59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28168 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2021-3749",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1d274e5e-9cea-5d2d-9838-f7708feeb27e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2023-45857",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3e372518-4fd7-5167-be7b-794e801f27d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2024-39338",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:30c5940e-dc11-50f7-bb07-ddb394974d26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39338 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fce97276-1257-54fa-9a79-ad99f198da65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2025-58754",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b663ccd2-11d2-5343-bb6a-8fbb1333837f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58754 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cf2ef713-11d6-52bc-95c6-1c9c931d83e3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 0.18.1-tuxcare.6 of axios. axios 0.18.1 has no no_proxy support at all (added upstream in 38de2525, first released in 0.19.0), so the no_proxy hostname-normalization matching loop this CVE bypasses does not exist; the proxy is resolved solely via getProxyForUrl() with no hostname matching.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:62fc19e7-7a2b-5781-aa0a-e4cbc8a5b8ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-39865",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:69d2b3a8-5f54-56df-9483-9b94e0a5afdf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-39865 does not affect version 0.18.1-tuxcare.6 of axios. not_affected \u2014 The target repository (axios 0.18.1-tuxcare.4) is not affected by CVE-2026-39865. This CVE describes an HTTP/2 session cleanup state corruption bug in the Http2Sessions class that was fixed in axios 1.13.2. The target version (0.18.1) predates the introduction of HTTP/2 support in axios, which was added in the 1.x series. The target's lib/adapters/http.js (302 lines) only supports HTTP/1.1 usin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0495c073-1b2d-5bd5-ae1c-73d88f27d61d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c55e25a6-7bb8-576d-82f1-7e8c42434e3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42033 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0539e410-38ed-5450-9c20-9380687bf23d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 0.18.1-tuxcare.6 of axios. axios 0.18.1 never reads config.maxBodyLength; lib/defaults.js defines only maxContentLength (a response-size limit), so there is no configurable request-body limit to bypass. Confirmed with a PoC against 0.18.1.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:92568bd8-909d-588f-85c4-0875e782877d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 0.18.1-tuxcare.6 of axios. Version 0.18.1 (SHA 3256bcea) is NOT affected by CVE-2026-42035. The vulnerable code path does not exist in this version. The attack requires two components: (1) a duck-typed isFormData() function that can be fooled by prototype pollution, and (2) code in lib/adapters/http.js that calls data.getHeaders() and merges the result into request headers. Version 0.18.1 has NEITHER: isFormData() uses instanceof (cannot be spoofed), and http.js has no getHeaders() call. The vulnerable code was introduced AFTER this version in a major ES6 rewrite (302\u2192751 lines), then fixed by commit 854c54e0 authored by CloudLinux engineer Krystyna Tomaszewa. Type A2: INPUT (plain object with polluted properties) is received but no code path reaches GOAL (header injection) because transformRequest JSON-stringifies plain objects before they reach the http adapter.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0c251ed0-e0d7-5b4a-aab3-fa4d6753fe43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:212b1ff2-ab83-5257-81e3-a860e46c8898",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 0.18.1-tuxcare.6 of axios. The loopback-equivalence bug lives entirely inside the no_proxy matching loop of lib/adapters/http.js, and axios 0.18.1 has no no_proxy support (added upstream in 38de2525, first released in 0.19.0); neither the matching loop nor isLoopbackHost.js exists.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b020c1f3-a60f-56c5-a8b6-b8105e3202db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6c4523ac-df75-50b0-b6e0-c7df9db4b522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42040 does not affect version 0.18.1-tuxcare.6 of axios. not_affected \u2014 Version 0.18.1 is not affected by CVE-2026-42040. The vulnerable component `lib/helpers/AxiosURLSearchParams.js` does not exist in this version\u2014it was introduced in v1.0.0-alpha.1 (commit 934f390c), which postdates 0.18.1. The buildURL.js encode function that exists in 0.18.1 does not contain the reverse-encoding charMap entry ('\"%00\": \"\\x00\"') that causes the vulnerability. Testing confirms th...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3135fcd8-a9d5-5db2-bf7a-8a9fced562be",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 0.18.1-tuxcare.6 of axios. not_affected \u2014 Axios v0.18.0 is NOT AFFECTED by CVE-2026-42041. The vulnerable code pattern (lib/core/mergeConfig.js with mergeDirectKeys function using the 'in' operator) was introduced in v0.22.0 (September 2021), more than 3 years after v0.18.0 was released (February 2018). Version 0.18.0 uses a completely different architecture: utils.merge() with forEach() that employs Object.prototype.hasOwnProperty che...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b7ea5873-cf2a-5619-89da-6f94f8753e17",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 0.18.1-tuxcare.6 of axios. not_affected \u2014 The target version (axios 0.18.1) is NOT AFFECTED by CVE-2026-42042. The vulnerability concerns the `withXSRFToken` configuration property introduced in later axios versions. Version 0.18.1 predates this feature and uses a completely different XSRF token mechanism based on the `withCredentials` property. Exhaustive searches confirm `withXSRFToken` does not exist anywhere in the codebase, and th...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5649ea7f-d95c-5581-9980-fdf26771b6cd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 0.18.1-tuxcare.6 of axios. Target version 0.18.1 is not affected by CVE-2026-42043. The vulnerability describes an incomplete fix in lib/helpers/shouldBypassProxy.js (lines 1-3) where a hardcoded loopback address set recognizes only 127.0.0.1 instead of the full 127.0.0.0/8 subnet. Version 0.18.1 does not contain this file or any NO_PROXY handling logic. NO_PROXY support was first introduced in axios v0.19.0 (August 2018), and version 0.18.1 predates this feature entirely. The vulnerable code pattern is not present.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c6f14e31-8060-5ee0-b5e1-8ce1488148d1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44486 does not affect version 0.18.1-tuxcare.6 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44486 (Proxy-Authorization header leak on redirect). The fix was backported in commit 806a27b (also 3a086d9 in a backport branch), which implements the exact same defense as vendor commit afca61a070728e717203c2bc21e7b589b59b858b.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6de222fd-2ca1-5e69-9daf-0042b93ca945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44487 does not affect version 0.18.1-tuxcare.6 of axios. already_fixed \u2014 The target repository already contains the fix for CVE-2026-44487 (GHSA-j5f8-grm9-p9fc). The exact vendor commit afca61a070728e717203c2bc21e7b589b59b858b was backported in commit 806a27b as part of CVE-2024-28849 remediation on April 28, 2026. The defense mechanism strips stale Proxy-Authorization headers on redirect re-invocations, preventing credential leakage to unintended recipients.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:15eb29e8-4d36-5744-8b3f-cafd6962c9ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:39987cd9-2119-5d63-abe8-1788e0eb440b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 0.18.1-tuxcare.6 of axios. not_affected \u2014 The target repository axios v0.18.1-tuxcare.2 does not implement NO_PROXY functionality at all. The vulnerability CVE-2026-44492 is specific to shouldBypassProxy.js (introduced in v1.15.0) which handles NO_PROXY hostname comparison. Since v0.18.1 predates this feature and has no hostname comparison or bypass logic, the vulnerability pattern cannot manifest.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:48da4342-b173-504a-8fc5-18cfccddc8c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-67316",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:40a7aaf8-3c43-535d-a68c-7694afd65a84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67316 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-67319",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d2c05076-1aca-5908-b6d8-0b638ca6baa5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-67319 is fixed in version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f796b45d-ffb5-5e17-8826-a9ce1df357a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.18.1-tuxcare.6 of axios."
      }
    },
    {
      "id": "GHSA-f2r5-pqh9-r8f8",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:222a11fa-adf9-52f1-927e-f9f75583bf46",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-f2r5-pqh9-r8f8 is a false positive for axios 0.18.1-tuxcare.6."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:75e7275a-2223-5c72-875a-8b8da0b00646",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.18.1-tuxcare.6 of axios."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.18.1-tuxcare.6"
    }
  ]
}