{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fb634ee8-646f-5ebf-8b8b-268de96afc8d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "h3",
      "purl": "pkg:npm/h3@1.15.3-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/h3@1.15.3-tuxcare.1",
      "version": "1.15.3-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-23527",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8f2b87d2-3fe3-58a8-979e-82e65e23ce6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23527 is fixed in version 1.15.3-tuxcare.1 of h3."
      }
    },
    {
      "id": "CVE-2026-33128",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8209a8e7-1b37-50db-8e73-b2ca970b82b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33128 is fixed in version 1.15.3-tuxcare.1 of h3."
      }
    },
    {
      "id": "CVE-2026-33129",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:07aca87b-308a-5236-8b1b-dffaa42c65ee",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33129 does not affect version 1.15.3-tuxcare.1 of h3. not_affected \u2014 Target version 1.15.3 is not affected by CVE-2026-33129. The basic authentication feature (requireBasicAuth function) was introduced in version 1.15.8, which postdates the target version by 5 releases. The vulnerable code pattern never existed in v1.15.3 because the entire authentication module (src/utils/auth.ts) does not exist in this version. The CVE affects versions 2.0.1-beta.0 through 2.0...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-33490",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9285218d-56fa-5ec1-9f12-0b158f363f10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33490 affects version 1.15.3-tuxcare.1 of h3."
      }
    },
    {
      "id": "GHSA-4hxc-9384-m385",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cc2e56a1-833d-5ed7-9f9b-7ab912427316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4hxc-9384-m385 affects version 1.15.3-tuxcare.1 of h3, and is fixed in 1.15.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-72gr-qfp7-vwhw",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5538afd9-8d5b-56cd-bcb8-11dc67cee46b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-72gr-qfp7-vwhw affects version 1.15.3-tuxcare.1 of h3, and is fixed in 1.15.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-wr4h-v87w-p3r7",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e417f75c-ce3e-5dd6-b4d3-17ac4d451129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wr4h-v87w-p3r7 affects version 1.15.3-tuxcare.1 of h3."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/h3@1.15.3-tuxcare.1"
    }
  ]
}