{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cd4a58bc-3298-587c-b326-f2f53d16fa8d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/tar@6.2.1-tuxcare.3",
      "type": "library",
      "name": "tar",
      "version": "6.2.1-tuxcare.3",
      "purl": "pkg:npm/tar@6.2.1-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3ae30c3f-139e-5378-9e64-3b15869be245",
      "id": "CVE-2026-23745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23745 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f920ea-b3b6-5109-a2b8-fada2051948e",
      "id": "CVE-2026-23950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23950 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f6f027c-355d-56e5-9255-a9a584610813",
      "id": "CVE-2026-24842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24842 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6509e807-a767-58ef-9b3a-521e53fef704",
      "id": "CVE-2026-26960",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26960 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad98a77-8eff-5ad8-a7d8-c15efdd2a618",
      "id": "CVE-2026-29786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29786 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5ae06e-2026-5b6b-bd0a-d53f77c13615",
      "id": "CVE-2026-31802",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31802 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de3ebe81-747a-5ace-ad27-e85159c4d723",
      "id": "CVE-2026-53655",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53655 is fixed in version 6.2.1-tuxcare.3 of tar."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ca01966-1f72-5135-9ab8-e40c2173c672",
      "id": "GHSA-qffp-2rhf-9h96",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-qffp-2rhf-9h96 does not affect version 6.2.1-tuxcare.3 of tar. already_fixed \u2014 The target repository (tar 6.2.1-tuxcare.3) already contains a backport of the vendor fix for GHSA-qffp-2rhf-9h96. The fix was applied in commit 4b41989e on March 13, 2026, which backported CVE-2026-29786 (the CVE identifier corresponding to GHSA-qffp-2rhf-9h96). The defense strips drive-relative root prefixes (like 'C:') from paths BEFORE checking for parent directory traversal sequences ('..')."
      },
      "affects": [
        {
          "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/tar@6.2.1-tuxcare.3"
    }
  ]
}