{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af3e8a97-1132-5081-ad80-6376e6efa71d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "h3",
      "purl": "pkg:npm/h3@1.15.3-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/h3@1.15.3-tuxcare.2",
      "version": "1.15.3-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-23527",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:627cc046-dc36-5b33-aae9-959b8a94ee74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23527 is fixed in version 1.15.3-tuxcare.2 of h3."
      }
    },
    {
      "id": "CVE-2026-33128",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:64790716-4ee8-57b8-a7f0-a16708cc4c20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33128 is fixed in version 1.15.3-tuxcare.2 of h3."
      }
    },
    {
      "id": "CVE-2026-33129",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:47ce411e-1a88-5822-b229-092088b75517",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33129 does not affect version 1.15.3-tuxcare.2 of h3. not_affected \u2014 Target version 1.15.3 is not affected by CVE-2026-33129. The basic authentication feature (requireBasicAuth function) was introduced in version 1.15.8, which postdates the target version by 5 releases. The vulnerable code pattern never existed in v1.15.3 because the entire authentication module (src/utils/auth.ts) does not exist in this version. The CVE affects versions 2.0.1-beta.0 through 2.0...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-33490",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:43d221f1-6d3f-5f9b-a49d-e3773392cffa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33490 affects version 1.15.3-tuxcare.2 of h3."
      }
    },
    {
      "id": "GHSA-4hxc-9384-m385",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e682ab7-0c00-5876-8cd1-58b0ef153ca9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4hxc-9384-m385 is fixed in version 1.15.3-tuxcare.2 of h3."
      }
    },
    {
      "id": "GHSA-72gr-qfp7-vwhw",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dc6b5e06-46b3-51b2-8d02-14ba811521ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-72gr-qfp7-vwhw is fixed in version 1.15.3-tuxcare.2 of h3."
      }
    },
    {
      "id": "GHSA-wr4h-v87w-p3r7",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a6855883-7e70-50d3-a71d-0d378610b3d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wr4h-v87w-p3r7 affects version 1.15.3-tuxcare.2 of h3."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/h3@1.15.3-tuxcare.2"
    }
  ]
}