{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:36cf8f0b-3929-56c7-b0cb-9228a6a7276e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "h3",
      "purl": "pkg:npm/h3@1.15.3",
      "type": "library",
      "bom-ref": "pkg:npm/h3@1.15.3",
      "version": "1.15.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-23527",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:9785fc3d-f9db-5167-ac1b-f2b863d73e22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-23527 affects version 1.15.3 of h3, and is fixed in 1.15.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-33128",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:4d93704b-4c00-5752-86ed-f7b0e494db98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33128 affects version 1.15.3 of h3, and is fixed in 1.15.3-tuxcare.1."
      }
    },
    {
      "id": "CVE-2026-33129",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:1a202c16-00c4-57af-b28b-7eb79d07a725",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33129 does not affect version 1.15.3 of h3. not_affected \u2014 Target version 1.15.3 is not affected by CVE-2026-33129. The basic authentication feature (requireBasicAuth function) was introduced in version 1.15.8, which postdates the target version by 5 releases. The vulnerable code pattern never existed in v1.15.3 because the entire authentication module (src/utils/auth.ts) does not exist in this version. The CVE affects versions 2.0.1-beta.0 through 2.0...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-33490",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:ec9415ab-af6a-5ba9-a23b-e6bb4f9ca464",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33490 affects version 1.15.3 of h3."
      }
    },
    {
      "id": "GHSA-4hxc-9384-m385",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:b23a48ad-0923-58f9-896e-a1af39ee4b66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4hxc-9384-m385 affects version 1.15.3 of h3, and is fixed in 1.15.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-72gr-qfp7-vwhw",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:e6dc930b-31aa-5008-88fd-f94afc0c8dfc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-72gr-qfp7-vwhw affects version 1.15.3 of h3, and is fixed in 1.15.3-tuxcare.2."
      }
    },
    {
      "id": "GHSA-wr4h-v87w-p3r7",
      "affects": [
        {
          "ref": "pkg:npm/h3@1.15.3"
        }
      ],
      "bom-ref": "urn:uuid:bf9d8f20-1c71-50eb-bcf0-d1e1deab0021",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wr4h-v87w-p3r7 affects version 1.15.3 of h3."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/h3@1.15.3"
    }
  ]
}