{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d3f63aa9-9ef9-51a2-8afb-254f2dde1576",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p1+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b7c2e1d4-1a5d-5909-acf7-4aa6c45f1c2b",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05b78f0-6da4-529f-b881-0da82da1e41f",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94da944f-7c9c-52b2-9190-a7901b7fdf29",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c9bfb2-4a77-570f-a980-a669f015c136",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe34699-6439-50fe-ab8d-c98778da5784",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:374490c2-5f02-5dd7-9f71-b9bfbeb7a104",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dab53bff-13cf-51cd-97c1-6f87e5e16d67",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13080 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97917afb-afab-5281-adfa-1a69649042fc",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eafd0ae0-2f1c-5bb2-a20e-d33a5e18b867",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41068807-85c8-5b0c-932d-b15a61cfcb79",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e943d4-cdf6-53dc-89df-48109c50bc74",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c3664a8-e8d2-541b-b306-a0f1caf047de",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df53b01c-2fb1-55b8-9ff3-b8412c549740",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc149b38-9476-5436-8388-177dcd4ef0ac",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c660c9e1-114f-5289-b601-8744beaf3641",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6365 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4cd788-0781-50d0-81bc-b79cfcef28e8",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6366 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d2a783b-d197-5310-b3f5-6b7243ef48df",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-9082 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91928f8-fee6-5dff-b7df-21837ffb344b",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3a0a78-37d9-5b5a-a46b-fb4f5e4a0ea1",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p1+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
    }
  ]
}