{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e6a1420c-0766-5a94-afa4-ab65e5f768ca",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/devalue@4.3.2-tuxcare.1",
      "type": "library",
      "name": "devalue",
      "version": "4.3.2-tuxcare.1",
      "purl": "pkg:npm/devalue@4.3.2-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:70fa7805-5b75-55c1-810a-0741f6df38a9",
      "id": "CVE-2020-8203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-8203 is fixed in version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a77d39af-60b9-50a7-9d40-245a12fe2319",
      "id": "CVE-2025-57820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57820 is fixed in version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92471345-b879-5e38-a092-402dd0f46624",
      "id": "CVE-2026-22774",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22774 does not affect version 4.3.2-tuxcare.1 of devalue. Version 4.3.2 is not affected by CVE-2026-22774 because it lacks typed array parsing functionality entirely. The vulnerability exists in typed array hydration code that was introduced in version 5.1.0, well after this version. When typed array data is provided to v4.3.2, it throws \"Unknown type\" error before any DoS can occur."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f6535c9-8f66-5828-b66f-31ce119fc6d8",
      "id": "CVE-2026-30226",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-30226 is fixed in version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f75db25c-1f3a-5829-9d3d-a7e97b73976a",
      "id": "CVE-2026-42570",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42570 affects version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bcfea65-4997-5b81-b646-2c34d54c717d",
      "id": "GHSA-33hq-fvwr-56pm",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-33hq-fvwr-56pm affects version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb1803a7-11cb-5ce9-8510-f6d07f19cb44",
      "id": "GHSA-8qm3-746x-r74r",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8qm3-746x-r74r is fixed in version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e7d759d-2de6-58f0-8f8b-b89f9f66bf01",
      "id": "GHSA-mwv9-gp5h-frr4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mwv9-gp5h-frr4 is fixed in version 4.3.2-tuxcare.1 of devalue."
      },
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/devalue@4.3.2-tuxcare.1"
    }
  ]
}