{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:48cfc65f-4ee9-5b80-ac7f-a39b39858973",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "axios",
      "purl": "pkg:npm/axios@0.15.3-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/axios@0.15.3-tuxcare.6",
      "version": "0.15.3-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2019-10742",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:08475810-6f60-5fe1-826f-a0fffc13cdd7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10742 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2020-28168",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01431fd3-86e5-5abe-bd77-83b4c792374c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-28168 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2021-3749",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a0154ae0-4d08-5f50-9e23-7968f5303c71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3749 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2023-45857",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d4b2e057-9c09-5d2c-a3e0-69bd64a6973f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45857 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2024-39338",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:785ae926-60a1-5d8b-a44c-ed8e0eca9212",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39338 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2025-27152",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:79d929ad-20eb-5307-a32d-6c785d8dd49f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27152 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2025-62718",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fdb36950-539c-5ccc-9cf3-5045a0711073",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62718 does not affect version 0.15.3-tuxcare.6 of axios. axios 0.15.3 has no no_proxy support at all (added upstream in 38de2525, first released in 0.19.0), so the no_proxy hostname-normalization matching loop this CVE bypasses does not exist; the proxy is resolved solely via getProxyForUrl() with no hostname matching.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-25639",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1fa107c0-5501-5404-a62f-9da1b29cf2a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25639 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-40175",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:08d7c10b-a458-5b19-8e83-f50dbc9bfd3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40175 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42033",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6eabde4d-a42a-593f-aa88-2fa16f687fb9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42033 does not affect version 0.15.3-tuxcare.6 of axios. axios 0.15.3 contains none of the prototype-pollution gadgets the advisory lists: config.transport, the mergeConfig transformRequest/transformResponse reads and the other sinks were all introduced in 0.19.0 or later. The advisory's <= 0.31.0 range is a blanket range; every per-gadget scope starts above 0.15.3.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42034",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5f765ec1-b567-5a1c-843a-3d484a44b530",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42034 does not affect version 0.15.3-tuxcare.6 of axios. axios 0.15.3 has no config.maxBodyLength option (only maxContentLength, a response-size limit), and lib/adapters/http.js never sets options.maxBodyLength, so there is no request-body size limit to bypass. Confirmed with a PoC against 0.15.3.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42035",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:620a3636-fd37-5024-bf07-07297a8afd1a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42035 does not affect version 0.15.3-tuxcare.6 of axios. Version 0.15.3 is not affected by CVE-2026-42035. The vulnerability requires duck-type FormData checking combined with calling data.getHeaders() to merge polluted headers into requests. This code pattern was introduced in later Axios versions but does not exist in 0.15.3. The target uses a simple instanceof FormData check (no duck-typing) and never invokes data.getHeaders(). Plain objects passed as request data are JSON-stringified as the request body and cannot influence headers. Attack Vector Brief: INPUT=plain object with polluted Object.prototype; GOAL=arbitrary headers merged into request; DEFENSE=reject plain objects in FormData check AND ensure getHeaders is not inherited. Target architecture predates the vulnerable pattern entirely.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42036",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a986c11a-729d-59a1-ae5e-547a12a05a4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42036 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42038",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:135e681d-6471-5d41-8553-e87990c1b4c2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42038 does not affect version 0.15.3-tuxcare.6 of axios. The loopback-equivalence bug lives entirely inside the no_proxy matching loop of lib/adapters/http.js, and axios 0.15.3 has no no_proxy support (added upstream in 38de2525, first released in 0.19.0); neither the matching loop nor isLoopbackHost.js exists.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42039",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c06176aa-1e20-5e4e-a53a-66b29226eadf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42039 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-42040",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7931210f-6df6-5675-adff-f8e3769a0dfe",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42040 does not affect version 0.15.3-tuxcare.6 of axios. not_affected \u2014 Version 0.15.3 does not contain the vulnerable component lib/helpers/AxiosURLSearchParams.js, which was introduced in v1.0.0-alpha.1 (2022). The CVE describes a null byte injection vulnerability in the encode() function within AxiosURLSearchParams.js, specifically the charMap entry '%00': '\\x00' that reverses safe percent-encoding. This file and vulnerability pattern do not exist in 0.15.3. The...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42041",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5b50a987-7f35-52c7-a4a1-79d0a8639e59",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42041 does not affect version 0.15.3-tuxcare.6 of axios. not_affected \u2014 Version 0.15.3 is NOT AFFECTED by CVE-2026-42041. The vulnerability requires the mergeDirectKeys function (introduced in later axios versions ~1.x) which uses the `in` operator to check property existence, allowing prototype chain traversal. Version 0.15.3 uses a fundamentally different architecture: utils.merge() with a hasOwnProperty filter that has been present since the initial implementati...",
        "justification": "protected_at_runtime"
      }
    },
    {
      "id": "CVE-2026-42042",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01f552b4-7a96-52cf-a3b6-e08985a95265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42042 does not affect version 0.15.3-tuxcare.6 of axios. not_affected \u2014 Axios version 0.15.3 is NOT affected by CVE-2026-42042. The vulnerability targets the `withXSRFToken` configuration property, which was introduced in versions after 0.15.3. This version uses a different XSRF implementation based on the `withCredentials` property (introduced in v0.8.1 per CHANGELOG). The vulnerable code component (lib/helpers/resolveConfig.js) and the `withXSRFToken` feature are...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-42043",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:23f0da17-0cb9-5b7b-8a5a-370ce0aa5357",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42043 does not affect version 0.15.3-tuxcare.6 of axios. Incomplete-fix follow-up to CVE-2026-42038: the affected code is lib/helpers/isLoopbackHost.js, called only from the no_proxy matching loop. axios 0.15.3 has neither \u2014 no_proxy support first shipped in 0.19.0.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44486",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2d260a25-cc8c-5288-9934-ec2ee71fbd17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44486 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-44487",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e35b8e07-6564-59c8-a61d-7c4ecf397779",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44487 does not affect version 0.15.3-tuxcare.6 of axios. not_affected \u2014 Axios version 0.15.3 is not affected by CVE-2026-44487. The vulnerability requires dynamic proxy re-resolution on redirect (a feature introduced in axios 0.27.2), which is absent from version 0.15.3. In this version, all redirects unconditionally reuse the same proxy configuration as the initial request, preventing the proxy credential leak scenario described in the CVE.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44490",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f430c428-d77c-5b98-a5f0-669bfc9f5d7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44490 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "CVE-2026-44492",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:cd2aea14-f488-5306-b6e6-791425cfcfbe",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44492 does not affect version 0.15.3-tuxcare.6 of axios. not_affected \u2014 Target version 0.15.3-tuxcare.3 is NOT AFFECTED by CVE-2026-44492. The vulnerability requires the NO_PROXY environment variable mechanism to exist, which was not introduced until version 0.19.1 (commit 38de252, August 2018). The target version predates this feature entirely.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-44496",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9cddbecb-b874-5998-a716-79fcb66e2365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44496 is fixed in version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "GHSA-7q8q-rj6j-mhjq",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:08975e48-cfbd-5760-9f2f-78976c89e480",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7q8q-rj6j-mhjq affects version 0.15.3-tuxcare.6 of axios."
      }
    },
    {
      "id": "GHSA-f2r5-pqh9-r8f8",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ec1af7f8-bd55-5bfd-ba37-d16a04195149",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-f2r5-pqh9-r8f8 is a false positive for axios 0.15.3-tuxcare.6."
      }
    },
    {
      "id": "GHSA-mmx7-hfxf-jppx",
      "affects": [
        {
          "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:14919291-2a1f-536c-bc82-61180f6ce3a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mmx7-hfxf-jppx affects version 0.15.3-tuxcare.6 of axios."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/axios@0.15.3-tuxcare.6"
    }
  ]
}