{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ddb6d87a-c205-56de-aaf4-0d4d784b5034",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "devalue",
      "purl": "pkg:npm/devalue@5.9.1",
      "type": "library",
      "bom-ref": "pkg:npm/devalue@5.9.1",
      "version": "5.9.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-92708",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:e663545a-fc19-5ba2-a627-74e2c7d198ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-92708 affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
      }
    },
    {
      "id": "GHSA-4q55-j62x-fr9h",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:8f03bc61-6380-56ae-875a-b489ceea1c59",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-4q55-j62x-fr9h does not affect version 5.9.1 of devalue. not_affected \u2014 The target repository (devalue v5.9.1, SHA ef97051b) is NOT AFFECTED by GHSA-4q55-j62x-fr9h. The vulnerability\u2014where malicious payloads could cause `parse` to create objects with `__proto__` as an own property\u2014has been fixed by the upstream vendor. Two explicit checks in src/parse.js (lines 157-159 for null-prototype objects, lines 258-260 for regular objects) throw errors when `__proto__` is e...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-hx4r-w6wj-j8fg",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:eb338637-aaff-59af-a120-c8dc70dde633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-hx4r-w6wj-j8fg affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
      }
    },
    {
      "id": "GHSA-mcm9-63f2-9j32",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:67022465-3f8c-5f25-8091-72be23ce3f06",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-mcm9-63f2-9j32 does not affect version 5.9.1 of devalue. not_affected \u2014 The target version 5.9.1 is NOT affected by GHSA-mcm9-63f2-9j32. The vulnerability (sparse array amplification DoS) was fixed by upstream commit 819f1ac, which is present in version 5.9.1. The fix prevents the scenario where parsing a small serialized sparse array and passing it to uneval() could generate a massive output string by iterating millions of indices. Both stringify.js and uneval.js ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-r9w8-h9r3-54w4",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:fdd65f4a-8eba-52cb-843b-81132abbe1d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r9w8-h9r3-54w4 affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
      }
    },
    {
      "id": "GHSA-wf3x-273g-mvxv",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:719ce3d2-7328-5e9b-a9d4-faf066423a0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wf3x-273g-mvxv affects version 5.9.1 of devalue."
      }
    },
    {
      "id": "GHSA-x5rw-q4pp-hg5g",
      "affects": [
        {
          "ref": "pkg:npm/devalue@5.9.1"
        }
      ],
      "bom-ref": "urn:uuid:71ee2219-b5c9-5e85-9515-042036ab9805",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x5rw-q4pp-hg5g affects version 5.9.1 of devalue, and is fixed in 5.9.1-tuxcare.1."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/devalue@5.9.1"
    }
  ]
}