{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d185ebba-c768-5a2d-a053-8ec0fc756c53",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "brace-expansion",
      "purl": "pkg:npm/brace-expansion@1.1.14",
      "type": "library",
      "bom-ref": "pkg:npm/brace-expansion@1.1.14",
      "version": "1.1.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-5889",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:fe1c5a25-f5e9-5527-916a-909bc203c98f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5889 affects version 1.1.14 of brace-expansion."
      }
    },
    {
      "id": "CVE-2026-102276",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:849a0cb8-5c57-5dcb-94f1-5661bafbcadb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-102276 affects version 1.1.14 of brace-expansion, and is fixed in 1.1.14-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-102277",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:7b842d53-07bb-55f0-9d70-9d90c6e30d1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-102277 affects version 1.1.14 of brace-expansion, and is fixed in 1.1.14-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-102278",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:2a786d93-7481-5f67-9bce-070bab5beaa7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-102278 affects version 1.1.14 of brace-expansion, and is fixed in 1.1.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-13149",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:6a0804b3-4d69-571e-b6bf-cf5d6ae19d8a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-13149 affects version 1.1.14 of brace-expansion."
      }
    },
    {
      "id": "CVE-2026-14257",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:77ee0125-6208-58da-b9c9-785dff4158e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-14257 affects version 1.1.14 of brace-expansion."
      }
    },
    {
      "id": "CVE-2026-69152",
      "affects": [
        {
          "ref": "pkg:npm/brace-expansion@1.1.14"
        }
      ],
      "bom-ref": "urn:uuid:b1960c8b-80e7-5573-8cf6-d0e4431dc92b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69152 affects version 1.1.14 of brace-expansion."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/brace-expansion@1.1.14"
    }
  ]
}