{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:73ba192c-b234-50d2-ba9b-ee0a24d94428",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "devalue",
      "purl": "pkg:npm/devalue@4.3.2-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/devalue@4.3.2-tuxcare.2",
      "version": "4.3.2-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-57820",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6db1f86f-1927-58b9-86ca-3b87eae416a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57820 is fixed in version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "CVE-2026-22774",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38878d27-3077-548f-ab21-ad4399a3b7dd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22774 does not affect version 4.3.2-tuxcare.2 of devalue. Version 4.3.2 is not affected by CVE-2026-22774 because it lacks typed array parsing functionality entirely. The vulnerability exists in typed array hydration code that was introduced in version 5.1.0, well after this version. When typed array data is provided to v4.3.2, it throws \"Unknown type\" error before any DoS can occur.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-30226",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:30256039-35f5-59e7-aee9-31534f2922cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-30226 is fixed in version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "CVE-2026-42570",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:357bfb65-e479-598a-8d31-67ba81f7b948",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42570 affects version 4.3.2-tuxcare.2 of devalue, and is fixed in 4.3.2-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-81176",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dff388fd-6a99-5f43-9a41-7bee5744afc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-81176 affects version 4.3.2-tuxcare.2 of devalue, and is fixed in 4.3.2-tuxcare.3."
      }
    },
    {
      "id": "GHSA-33hq-fvwr-56pm",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:da3b62aa-187c-5116-b0bc-b936547c6a17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-33hq-fvwr-56pm is fixed in version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-4q55-j62x-fr9h",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60b27aff-ee87-5333-97dc-9073e5ba727d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4q55-j62x-fr9h affects version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-8qm3-746x-r74r",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9e9cd650-82f8-5c8c-8107-f246afa580e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8qm3-746x-r74r is fixed in version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-8qm3-746x-r74r-map-keys",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a899b533-f697-502c-a092-23284e9c2a05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8qm3-746x-r74r-map-keys is fixed in version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-hx4r-w6wj-j8fg",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5bdd0451-203e-5bee-b6cf-ae068b75abb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-mcm9-63f2-9j32",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cab4a2b2-6553-5993-8dfd-f38945790d61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mcm9-63f2-9j32 affects version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-mwv9-gp5h-frr4",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cedeb77a-f3c9-5f8b-8697-38f2f399b5aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mwv9-gp5h-frr4 is fixed in version 4.3.2-tuxcare.2 of devalue."
      }
    },
    {
      "id": "GHSA-r9w8-h9r3-54w4",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a4547f5a-4027-593d-ad0e-5bca0fa0f18e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-r9w8-h9r3-54w4 does not affect version 4.3.2-tuxcare.2 of devalue. not_affected \u2014 Version 4.3.2 is NOT affected by GHSA-r9w8-h9r3-54w4. The vulnerability requires built-in ArrayBuffer deserialization code, which does not exist in this version. ArrayBuffer support was introduced in v5.1.0 (commit bbf86c2, September 2023), significantly later than v4.3.2. Exhaustive code search and git history analysis confirm complete absence of ArrayBuffer, TypedArray, DataView, and base64 e...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-wf3x-273g-mvxv",
      "affects": [
        {
          "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8ad80ee5-788c-5140-ae1e-294fe9ef5465",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wf3x-273g-mvxv affects version 4.3.2-tuxcare.2 of devalue."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/devalue@4.3.2-tuxcare.2"
    }
  ]
}