{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8dd76fe1-c620-5b65-854a-ecbf8afc4d33",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.1-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:855293c8-c2f3-5522-b5af-aba21d6fa623",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01bdd4d4-e17c-5433-964c-364df643670d",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:101713de-49c8-51ed-b968-a3d19ef8d83a",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4f6998-4082-5416-a809-d36083390885",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01295ec3-aeca-5cdb-8438-7ff779c841d3",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e413b470-748c-520a-a581-bbe7f5e1b315",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p1+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c87f6274-d929-591f-931c-919df1d277f2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb611376-0987-5c34-a6ac-fa8a72d054ce",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a9d1bd-6b65-5b7c-9eb3-736b30ce6794",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8135816e-0a06-58cb-bba3-cb28d905103b",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99cd421f-b08a-5c98-b2bb-4d6ce2177385",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69860cc0-b076-5b66-a378-490fb6187f8a",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
    }
  ]
}