{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3ff01aea-adde-56bc-9bcb-3224f80a09e9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "7.10.0-p2+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/ratchet/pawl@v0.1.2-p2+tuxcare",
      "type": "library",
      "group": "ratchet",
      "name": "pawl",
      "version": "v0.1.2-p2+tuxcare",
      "purl": "pkg:composer/ratchet/pawl@v0.1.2-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/voryx/thruway@0.4.2-p2+tuxcare",
      "type": "library",
      "group": "voryx",
      "name": "thruway",
      "version": "0.4.2-p2+tuxcare",
      "purl": "pkg:composer/voryx/thruway@0.4.2-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p6+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
      "type": "library",
      "group": "twig",
      "name": "twig",
      "version": "v2.15.6-p2+tuxcare",
      "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
      "type": "library",
      "group": "twig",
      "name": "twig",
      "version": "v2.16.1-p2+tuxcare",
      "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "12.58.0-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p7+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.1-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.2-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "yaml",
      "version": "v4.4.45-p2+tuxcare",
      "purl": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "8.9.20-p1+tuxcare",
      "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/cboden/ratchet@v0.3.6-p4+tuxcare",
      "type": "library",
      "group": "cboden",
      "name": "ratchet",
      "version": "v0.3.6-p4+tuxcare",
      "purl": "pkg:composer/cboden/ratchet@v0.3.6-p4+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "yaml",
      "version": "v2.8.52-p1+tuxcare",
      "purl": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "yaml",
      "version": "v3.4.47-p2+tuxcare",
      "purl": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.3-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "6.5.8-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p5+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "9.52.21-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/monolog/monolog@1.11.0-p1+tuxcare",
      "type": "library",
      "group": "monolog",
      "name": "monolog",
      "version": "1.11.0-p1+tuxcare",
      "purl": "pkg:composer/monolog/monolog@1.11.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p6+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "yaml",
      "version": "v3.4.47-p1+tuxcare",
      "purl": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
      "type": "library",
      "group": "verbb",
      "name": "feed-me",
      "version": "3.1.17-p2+tuxcare",
      "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "7.30.7-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "yaml",
      "version": "v4.4.45-p1+tuxcare",
      "purl": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.83.29-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/voryx/thruway@0.4.2-p1+tuxcare",
      "type": "library",
      "group": "voryx",
      "name": "thruway",
      "version": "0.4.2-p1+tuxcare",
      "purl": "pkg:composer/voryx/thruway@0.4.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
      "type": "library",
      "group": "twig",
      "name": "twig",
      "version": "v2.16.1-p1+tuxcare",
      "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "6.0.2-p3+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "psr7",
      "version": "1.4.2-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
      "type": "library",
      "group": "twig",
      "name": "twig",
      "version": "v2.15.6-p1+tuxcare",
      "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "psr7",
      "version": "1.9.1-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/ratchet/pawl@v0.1.2-p1+tuxcare",
      "type": "library",
      "group": "ratchet",
      "name": "pawl",
      "version": "v0.1.2-p1+tuxcare",
      "purl": "pkg:composer/ratchet/pawl@v0.1.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare",
      "type": "library",
      "group": "aws",
      "name": "aws-sdk-php",
      "version": "3.263.4-p3+tuxcare",
      "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare",
      "type": "library",
      "group": "cakephp",
      "name": "cakephp",
      "version": "2.10.24-p2+tuxcare",
      "purl": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p5+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
      "type": "library",
      "group": "phpoffice",
      "name": "phpspreadsheet",
      "version": "4.5.0-p2+tuxcare",
      "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p4+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/http-kernel@v7.4.10-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "http-kernel",
      "version": "v7.4.10-p1+tuxcare",
      "purl": "pkg:composer/symfony/http-kernel@v7.4.10-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laminas/laminas-http@2.5.6-p1+tuxcare",
      "type": "library",
      "group": "laminas",
      "name": "laminas-http",
      "version": "2.5.6-p1+tuxcare",
      "purl": "pkg:composer/laminas/laminas-http@2.5.6-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/mailer@v6.4.34-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "mailer",
      "version": "v6.4.34-p1+tuxcare",
      "purl": "pkg:composer/symfony/mailer@v6.4.34-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "laravel-medialibrary",
      "version": "9.12.4-p2+tuxcare",
      "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "routing",
      "version": "v4.4.44-p1+tuxcare",
      "purl": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "routing",
      "version": "v3.4.47-p1+tuxcare",
      "purl": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "6.0.2-p2+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "7.10.0-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "9.52.21-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "10.48.29-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "laravel-medialibrary",
      "version": "10.15.0-p2+tuxcare",
      "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "mime",
      "version": "v5.4.45-p1+tuxcare",
      "purl": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "6.0.2-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "mime",
      "version": "v6.4.37-p2+tuxcare",
      "purl": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p4+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
      "type": "library",
      "group": "phpseclib",
      "name": "phpseclib",
      "version": "0.3.10-p3+tuxcare",
      "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/http-kernel@v3.4.49-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "http-kernel",
      "version": "v3.4.49-p1+tuxcare",
      "purl": "pkg:composer/symfony/http-kernel@v3.4.49-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "10.48.28-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "routing",
      "version": "v5.4.48-p1+tuxcare",
      "purl": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "10.50.2-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare",
      "type": "library",
      "group": "zendframework",
      "name": "zend-http",
      "version": "2.5.6-p2+tuxcare",
      "purl": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "11.44.0-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "12.58.0-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "11.51.0-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/mailer@v7.4.8-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "mailer",
      "version": "v7.4.8-p1+tuxcare",
      "purl": "pkg:composer/symfony/mailer@v7.4.8-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare",
      "type": "library",
      "group": "zendframework",
      "name": "zendframework",
      "version": "2.4.13-p1+tuxcare",
      "purl": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "routing",
      "version": "v7.4.9-p1+tuxcare",
      "purl": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "routing",
      "version": "v6.4.37-p1+tuxcare",
      "purl": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "mime",
      "version": "v7.4.9-p1+tuxcare",
      "purl": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "mime",
      "version": "v6.4.37-p1+tuxcare",
      "purl": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laminas/laminas-diactoros@2.22.0-p1+tuxcare",
      "type": "library",
      "group": "laminas",
      "name": "laminas-diactoros",
      "version": "2.22.0-p1+tuxcare",
      "purl": "pkg:composer/laminas/laminas-diactoros@2.22.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare",
      "type": "library",
      "group": "aws",
      "name": "aws-sdk-php",
      "version": "3.263.4-p2+tuxcare",
      "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.8.38-p4+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "10.48.28-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/cboden/ratchet@v0.3.6-p3+tuxcare",
      "type": "library",
      "group": "cboden",
      "name": "ratchet",
      "version": "v0.3.6-p3+tuxcare",
      "purl": "pkg:composer/cboden/ratchet@v0.3.6-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p3+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/cboden/ratchet@v0.3.6-p2+tuxcare",
      "type": "library",
      "group": "cboden",
      "name": "ratchet",
      "version": "v0.3.6-p2+tuxcare",
      "purl": "pkg:composer/cboden/ratchet@v0.3.6-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
      "type": "library",
      "group": "phpseclib",
      "name": "phpseclib",
      "version": "0.3.10-p2+tuxcare",
      "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare",
      "type": "library",
      "group": "swiftmailer",
      "name": "swiftmailer",
      "version": "6.0.2-p1+tuxcare",
      "purl": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@4.8.10-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "4.8.10-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@4.8.10-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare",
      "type": "library",
      "group": "zendframework",
      "name": "zend-http",
      "version": "2.5.6-p1+tuxcare",
      "purl": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/cboden/ratchet@v0.3.6-p1+tuxcare",
      "type": "library",
      "group": "cboden",
      "name": "ratchet",
      "version": "v0.3.6-p1+tuxcare",
      "purl": "pkg:composer/cboden/ratchet@v0.3.6-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
      "type": "library",
      "group": "phpseclib",
      "name": "phpseclib",
      "version": "0.3.10-p1+tuxcare",
      "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
      "type": "library",
      "group": "guzzlehttp",
      "name": "guzzle",
      "version": "6.3.3-p1+tuxcare",
      "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "http-foundation",
      "version": "3.4.47-p3+tuxcare",
      "purl": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare",
      "type": "library",
      "group": "google",
      "name": "protobuf",
      "version": "3.24.4-p1+tuxcare",
      "purl": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.8.38-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "9.52.21-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare",
      "type": "library",
      "group": "nategood",
      "name": "httpful",
      "version": "0.3.2-p1+tuxcare",
      "purl": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.83.29-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "6.20.45-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "7.30.7-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "11.51.0-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "10.50.2-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.8.38-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p2+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "12.58.0-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
      "type": "library",
      "group": "zendframework",
      "name": "zendframework1",
      "version": "1.12.10-p2+tuxcare",
      "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/league/flysystem@1.0.70-p1+tuxcare",
      "type": "library",
      "group": "league",
      "name": "flysystem",
      "version": "1.0.70-p1+tuxcare",
      "purl": "pkg:composer/league/flysystem@1.0.70-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/league/flysystem@1.1.10-p1+tuxcare",
      "type": "library",
      "group": "league",
      "name": "flysystem",
      "version": "1.1.10-p1+tuxcare",
      "purl": "pkg:composer/league/flysystem@1.1.10-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.5.50-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.4.36-p4+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "browsershot",
      "version": "4.4.0-p2+tuxcare",
      "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/doctrine/orm@2.8.3-p1+tuxcare",
      "type": "library",
      "group": "doctrine",
      "name": "orm",
      "version": "2.8.3-p1+tuxcare",
      "purl": "pkg:composer/doctrine/orm@2.8.3-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
      "type": "library",
      "group": "league",
      "name": "commonmark",
      "version": "2.7.1-p1+tuxcare",
      "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p3+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@8.4.3-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "8.4.3-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@8.4.3-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@7.5.20-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "7.5.20-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@7.5.20-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@9.5.28-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "9.5.28-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@9.5.28-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@6.5.14-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "6.5.14-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@6.5.14-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
      "type": "library",
      "group": "league",
      "name": "commonmark",
      "version": "1.6.7-p3+tuxcare",
      "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@10.4.2-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "10.4.2-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@10.4.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.0-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.2-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.1-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.3-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p1+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare",
      "type": "library",
      "group": "saloonphp",
      "name": "saloon",
      "version": "3.15.0-p1+tuxcare",
      "purl": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p2+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.0-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "http-foundation",
      "version": "4.4.49-p2+tuxcare",
      "purl": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p1+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
      "type": "library",
      "group": "verbb",
      "name": "feed-me",
      "version": "3.1.17-p1+tuxcare",
      "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.4.36-p3+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare",
      "type": "library",
      "group": "phenx",
      "name": "php-svg-lib",
      "version": "0.3.4-p1+tuxcare",
      "purl": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@11.4.4-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "11.4.4-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@11.4.4-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.6.40-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.5.50-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.7.29-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.4.36-p2+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/process@3.4.47-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "process",
      "version": "3.4.47-p1+tuxcare",
      "purl": "pkg:composer/symfony/process@3.4.47-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare",
      "type": "library",
      "group": "illuminate",
      "name": "database",
      "version": "5.4.36-p2+tuxcare",
      "purl": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare",
      "type": "library",
      "group": "illuminate",
      "name": "database",
      "version": "5.4.36-p1+tuxcare",
      "purl": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpunit/phpunit@12.4.5-p1+tuxcare",
      "type": "library",
      "group": "phpunit",
      "name": "phpunit",
      "version": "12.4.5-p1+tuxcare",
      "purl": "pkg:composer/phpunit/phpunit@12.4.5-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
      "type": "library",
      "group": "league",
      "name": "commonmark",
      "version": "1.6.7-p2+tuxcare",
      "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/process@5.4.45-p2+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "process",
      "version": "5.4.45-p2+tuxcare",
      "purl": "pkg:composer/symfony/process@5.4.45-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/process@4.4.44-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "process",
      "version": "4.4.44-p1+tuxcare",
      "purl": "pkg:composer/symfony/process@4.4.44-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/process@6.4.13-p2+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "process",
      "version": "6.4.13-p2+tuxcare",
      "purl": "pkg:composer/symfony/process@6.4.13-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
      "type": "library",
      "group": "zendframework",
      "name": "zendframework1",
      "version": "1.12.10-p1+tuxcare",
      "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/nesbot/carbon@1.39.1-p1+tuxcare",
      "type": "library",
      "group": "nesbot",
      "name": "carbon",
      "version": "1.39.1-p1+tuxcare",
      "purl": "pkg:composer/nesbot/carbon@1.39.1-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare",
      "type": "library",
      "group": "phpmailer",
      "name": "phpmailer",
      "version": "5.2.28-p1+tuxcare",
      "purl": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "browsershot",
      "version": "4.4.0-p1+tuxcare",
      "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "browsershot",
      "version": "3.61.0-p2+tuxcare",
      "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare",
      "type": "library",
      "group": "illuminate",
      "name": "view",
      "version": "5.4.36-p1+tuxcare",
      "purl": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare",
      "type": "library",
      "group": "aws",
      "name": "aws-sdk-php",
      "version": "3.263.4-p1+tuxcare",
      "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare",
      "type": "library",
      "group": "firebase",
      "name": "php-jwt",
      "version": "6.11.1-p2+tuxcare",
      "purl": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare",
      "type": "library",
      "group": "cakephp",
      "name": "cakephp",
      "version": "2.10.24-p1+tuxcare",
      "purl": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "browsershot",
      "version": "3.61.0-p1+tuxcare",
      "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare",
      "type": "library",
      "group": "firebase",
      "name": "php-jwt",
      "version": "6.11.1-p1+tuxcare",
      "purl": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "laravel-medialibrary",
      "version": "10.15.0-p1+tuxcare",
      "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare",
      "type": "library",
      "group": "spatie",
      "name": "laravel-medialibrary",
      "version": "9.12.4-p1+tuxcare",
      "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
      "type": "library",
      "group": "phpoffice",
      "name": "phpspreadsheet",
      "version": "4.5.0-p1+tuxcare",
      "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/yajra/laravel-datatables-oracle@10.11.4-p1+tuxcare",
      "type": "library",
      "group": "yajra",
      "name": "laravel-datatables-oracle",
      "version": "10.11.4-p1+tuxcare",
      "purl": "pkg:composer/yajra/laravel-datatables-oracle@10.11.4-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare",
      "type": "library",
      "group": "swiftmailer",
      "name": "swiftmailer",
      "version": "5.4.12-p1+tuxcare",
      "purl": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/yajra/laravel-datatables-oracle@9.21.2-p1+tuxcare",
      "type": "library",
      "group": "yajra",
      "name": "laravel-datatables-oracle",
      "version": "9.21.2-p1+tuxcare",
      "purl": "pkg:composer/yajra/laravel-datatables-oracle@9.21.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "http-foundation",
      "version": "2.8.52-p1+tuxcare",
      "purl": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.4.36-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "http-foundation",
      "version": "4.4.49-p1+tuxcare",
      "purl": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
      "type": "library",
      "group": "dompdf",
      "name": "dompdf",
      "version": "0.8.6-p1+tuxcare",
      "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
      "type": "library",
      "group": "league",
      "name": "commonmark",
      "version": "1.6.7-p1+tuxcare",
      "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
      "type": "library",
      "group": "dompdf",
      "name": "dompdf",
      "version": "1.2.2-p1+tuxcare",
      "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.8.38-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare",
      "type": "library",
      "group": "livewire",
      "name": "livewire",
      "version": "3.6.3-p1+tuxcare",
      "purl": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "11.44.0-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.83.29-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/process@5.4.45-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "process",
      "version": "5.4.45-p1+tuxcare",
      "purl": "pkg:composer/symfony/process@5.4.45-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/symfony/process@6.4.13-p1+tuxcare",
      "type": "library",
      "group": "symfony",
      "name": "process",
      "version": "6.4.13-p1+tuxcare",
      "purl": "pkg:composer/symfony/process@6.4.13-p1+tuxcare"
    },
    {
      "bom-ref": "pkg:composer/nesbot/carbon@1.26.6-p1+tuxcare",
      "type": "library",
      "group": "nesbot",
      "name": "carbon",
      "version": "1.26.6-p1+tuxcare",
      "purl": "pkg:composer/nesbot/carbon@1.26.6-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:af76843a-235d-564b-8f64-917f9f8b6706",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55568 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97d7041e-c388-54fe-be20-6b37588c81bc",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55767 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d911269-966f-5165-b83e-204c86b12414",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59883 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71279fae-c6f2-5361-972b-1873214385b6",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:294c346a-2bec-5df2-bc17-a467f85b2593",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f3559e-4f75-5364-a7d9-c9c372eada07",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d8151ea-f1c8-5803-8d83-d55d2f0c124f",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a9dd46-c3ce-58cd-9642-47acfc0320d6",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e37184b4-1dd5-5907-97c4-2e9284f44cd3",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd66009c-08cf-53e3-b5af-93420b37b2be",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ff152c3-fa77-587d-8db1-bc05162bd7b3",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86d916f2-2888-5d46-a743-4af02cc5d00c",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c059524-6f8a-5c66-99b6-0aaa45f2d540",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a48d29-f741-5827-a139-05869f134464",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:591bbab1-71d8-55cc-b880-e03c1e3c032f",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13081 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5828f16-c2b0-5974-917b-9b6993771496",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13082 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77ecb9df-6d0c-5fe1-901d-9948d48bb05a",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13083 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4e23791-cadd-5735-8bc7-bde03e4ba83d",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2007b883-fae2-5a44-bcb3-05ceed73be29",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1704313e-f501-551d-b311-5df05478abf1",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f18868-df07-5754-a422-d417b3053b57",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b00617-bd65-5c84-813b-5e8798225727",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db7dccff-fcd3-582c-8216-274b769a5164",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2656337b-0d9a-5726-9a23-925d6328dac5",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e533134e-fb8e-5763-8fe5-c935d67fb328",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p6+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6756137-ba9b-58d7-8046-3bc49b090008",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p6+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2f3991e-4614-5257-8dbb-02f2aaa7cb99",
      "id": "CVE-2015-7809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-7809 does not affect version v2.15.6-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is running Twig 2.15.6, which is significantly newer than the vulnerable versions. The security fix that prevents arbitrary code execution via the _self variable in Sandbox mode is present in the target code at src/Template.php lines 175-178, with explicit documentation ('avoid RCEs when sandbox is enabled') and test coverage."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65032d89-cdf7-55da-aff7-85bb2cdee00a",
      "id": "CVE-2019-9942",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-9942 does not affect version v2.15.6-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 was fixed in Twig version 2.7.0 (released 2019-03-12). The target version 2.15.6 (released 2023-11-21) already contains the complete fix. The vulnerability allowed calling __toString() on objects in sandbox mode even when not allowed by the security policy. The fix introduces ensureToStringAllowed() method and CheckToStringNode wrapping mechanism that validates all implicit __toSt..."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d94c88-8879-5870-b7d9-c5e07c5fd0b0",
      "id": "CVE-2024-45411",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45411 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:667c75e0-f99a-57ff-8860-ee3d05a08386",
      "id": "CVE-2024-51754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51754 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0e979ab-a89e-538f-a225-779549e0ffce",
      "id": "CVE-2024-51755",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51755 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e463bb3-dcdd-5a48-b392-5441910473b9",
      "id": "CVE-2026-46628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46628 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d09cba9a-d3a7-585c-9d37-c0f0d71d6a2a",
      "id": "CVE-2026-46633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46633 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0668cf83-68ef-537b-95f5-1c93fd011ec8",
      "id": "CVE-2026-46635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46635 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cdd4f59-2869-5f79-af56-7bebf9b2195c",
      "id": "CVE-2026-46638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46638 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:853c0ade-7a67-5f3a-8717-7bdcdc22bbc6",
      "id": "CVE-2026-47732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47732 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99aa54d3-1acd-5189-b909-fe99ceb5577e",
      "id": "CVE-2026-48805",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48805 does not affect version v2.15.6-p2+tuxcare of twig/twig. not_affected \u2014 Twig v2.15.6 is not affected by CVE-2026-48805. The vulnerability exists only in Twig 3.26.0+ where architectural changes introduced deprecated wrapper functions in src/Resources/core.php that fail to forward sandbox state to CoreExtension methods. This architectural pattern does not exist in v2.15.6, which uses a different implementation where sandbox enforcement is correctly handled."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c306534-82c8-5a63-a3ba-a807dd54858a",
      "id": "CVE-2026-48806",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48806 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad6b493c-2152-5b6c-8e71-56cfe16e3573",
      "id": "CVE-2026-48807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48807 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a930dc59-80a5-5027-aeb6-abdee0490c10",
      "id": "CVE-2026-48808",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48808 does not affect version v2.15.6-p2+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48808 does not affect Twig 2.15.6 because it specifically targets a vulnerability in sandboxing enabled through SourcePolicyInterface, which does not exist in this version. The target uses a fundamentally different architecture predating the SourcePolicyInterface feature."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcb58c0a-37cd-5f22-a7cf-e691fa4cce26",
      "id": "CVE-2026-49981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49981 is fixed in version v2.15.6-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:495bf7e7-a6ac-5ed4-a2d6-40ee5f2615f0",
      "id": "CVE-2015-7809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-7809 does not affect version v2.16.1-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is Twig version 2.16.1, which contains the fix introduced in 1.20.0. The vulnerability allowed remote code execution via the _self variable in templates when Sandbox mode was enabled. The fix adds a type validation check in the displayBlock function that ensures template blocks must be instances of \\Twig\\Template, preventin..."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e981168f-cccf-5543-8f6d-0b7d5961f4a1",
      "id": "CVE-2019-9942",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-9942 does not affect version v2.16.1-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 has been fixed in Twig 2.16.1. The target contains the complete mitigation introduced in Twig 2.7.0 that prevents __toString() method calls from bypassing sandbox security policy restrictions."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f38cd33e-4512-507f-8309-a2d3e1208084",
      "id": "CVE-2024-51754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51754 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc0b8524-4eb7-5ed7-90cd-3b3127e6e080",
      "id": "CVE-2024-51755",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51755 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20df32fe-7c2e-572f-9749-9e807d749fc3",
      "id": "CVE-2026-24425",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24425 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcaea2d-fba8-5ac5-9099-140ae55adc97",
      "id": "CVE-2026-46628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46628 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db6e1432-15e7-5560-ab05-b9bb5e70c41d",
      "id": "CVE-2026-46633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46633 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed2c9931-0457-50bb-a0fa-32b713eb4aa2",
      "id": "CVE-2026-46635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46635 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7049b0d6-3f52-5373-8a3d-8c7524e9b54d",
      "id": "CVE-2026-46638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46638 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64cd50a3-67e4-597e-bf81-9bfb114fae48",
      "id": "CVE-2026-47732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47732 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf55421f-47f3-5d65-af09-3f7c9850d9c5",
      "id": "CVE-2026-48805",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48805 does not affect version v2.16.1-p2+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48805 describes a sandbox bypass in Twig v3.26.0 where deprecated wrapper functions in src/Resources/core.php fail to forward sandbox state to refactored CoreExtension class methods. Target v2.16.1 uses a completely different architecture where the vulnerable delegation pattern does not exist. The functions twig_array_some() and twig_array_every() don't exist in v2.16.1, and twig_check..."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e41aeb2-76ab-59cf-957d-f8289087f3fe",
      "id": "CVE-2026-48806",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48806 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d09cd5-0b3c-536e-b0df-8bd063da2bf5",
      "id": "CVE-2026-48807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48807 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce202365-0142-5337-a337-ea7db1bfc0df",
      "id": "CVE-2026-48808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48808 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7241a5f0-dcd8-5fe9-94a0-1366cd6c51a4",
      "id": "CVE-2026-49981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49981 is fixed in version v2.16.1-p2+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edb24c05-5178-5397-b1e4-c19a1d047d27",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 12.58.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7caf424d-6d89-55f5-a0ac-0100fe627acc",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 12.58.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1122f9dc-c5b3-55d6-84b1-fbc3e1671058",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp is fixed in version 12.58.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebcd4681-45b1-56bd-b0c1-0078eec7923b",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf03fc43-0ca7-5148-a1bf-9e2f1ba0fd6d",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bab3d63-381f-542b-aeec-1b2808d190f8",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd4ce26-d0d9-561d-acb7-33ed97d98189",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p7+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46cc3d6b-c1a8-5b9f-89a0-cb4dc2791c6a",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f289b5-59f0-5683-8927-15e2ea24727b",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d89ef53-6e16-51f3-8c52-aa00f8dd8678",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:963d29ba-30bb-5138-a97b-ffeab33e91bc",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9ce108-cc98-510a-ae2d-0b396f019613",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8c6224-b2e6-5c92-930a-86030e077a69",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54587856-3fb4-53d7-81e7-fb974149ef2c",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:396938b4-8ce8-5622-9c00-ec2413c97871",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c38c93b4-a12b-562d-b618-8131f696a584",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613525dc-6b2f-5db3-9ad5-c7282871364a",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac6cad18-9b3d-58b5-9aaa-b02e7ede29de",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45886f5d-6d98-5d07-81b3-ac84e50b35f0",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c589d3f-4deb-5060-b07d-a2b16f56d140",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:742a03cb-da44-5f18-b8d0-e89719fa47fe",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75e68fca-a12a-5ecf-a361-15927d987fa4",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c590ca2c-929f-52b4-9c74-49ade30b1bf8",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af9de098-02f2-587e-a23a-00902132fcc4",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad366d01-5a60-50b4-9097-62a49659e119",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a56b89c-6e06-532e-8b17-eb2d391460ba",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57811 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1882e69-b116-5dc9-a5e1-da0410742f4b",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d802e35-1278-581e-8905-71e37fb0a6f1",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66b0b825-75bd-58d0-a01b-12e2dbac21d1",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:917922a0-5b78-506c-bd57-d2f361a2d939",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e59ee061-b596-5fe6-8c63-5a0a8004e2aa",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16fe3221-f983-5d48-9773-53225d5bac63",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bea298d-f7c3-5d86-8ef6-516d4d2193c9",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f28edff2-b373-5ee6-abb8-dc4aec14e1e0",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25494 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b71c12e-a3ee-5ffa-9cd3-4e3d7154fce5",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59d099fc-8dc8-56bf-a9f6-8062ca4ed04a",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42bcc207-18e0-52d1-9403-c4fa5ba05d9b",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25498 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09019ea2-2d46-5d8a-90f6-e46a1d203381",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ed585f-e292-5650-a05e-a792f630228f",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c65a1e-9f52-5125-8bef-e14149ff8453",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de62be9b-4781-5168-918b-a1c1694163a2",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27129 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8baae358-5bc3-584d-ad07-7f8e56a68d5a",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:254ed075-e9e2-5813-943a-7d31d29c8fb4",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1c87773-7cce-53cc-a61c-cdec91618d95",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29113 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913107f8-b38a-59de-9644-e129a2ce4356",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6e735a-85a6-56f4-9086-2f28e4af99db",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70d30ab2-fb38-5fb4-ae90-d3cc752dfe4d",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31859 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:393410de-184e-5a14-8eab-43c095fc1b22",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9768593-215d-5da2-9bd9-913044c94f09",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31c29a59-f72e-509e-a8a3-f5755fca4157",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:076fc921-97a6-5891-8eb7-201234d2559e",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:443a89df-6fd1-537f-87b4-66b55327e580",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03620ab9-8025-57ea-95ef-148b843ac997",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba9d453-f732-539c-8981-e7d996a88107",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33158 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8364cab2-bba3-5612-b23f-dc86353454af",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33159 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:365f502f-4d23-5494-89c5-28a8e9a942ff",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611a6625-5f51-5522-aa62-33866ade6f6a",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33161 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb34d985-5f7a-57d0-8ba7-4f3ca8f46948",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d953db99-5f20-56f5-b0f0-7f4996b7c2c6",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac57de76-863b-55f3-8640-55f9443aada6",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d6b807-52c1-5241-8c07-dbba632cad9c",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fa84bc2-3960-59d3-b8db-f3bca389cc10",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bf7b952-f44d-5053-8c37-5e369a8d3a07",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc042f13-456e-58c0-9e6f-a0a705305b80",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7306413e-c798-5fb7-a5ed-e4d5660192a7",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31a6896d-9508-51ba-b241-6056e8ba1c5f",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9703f7fd-8dfd-5ccf-bd86-d63751876df0",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7fb77e2-de94-5115-b62e-48275cc7bbec",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9114ed1a-b95a-5730-a7a3-666f4d5dc4cf",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f53186-531d-5285-915d-7cea0cc3b955",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p7+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f5622b2-4ecd-534f-9030-4d0a38d08f0e",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b38ffc7e-a0b2-5a06-97a2-a691174c138f",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6295420b-7738-5c56-831c-8e8229595350",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c28dc5-f08a-5d41-b39b-f66408dfb8f7",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e48331ea-e7ee-5b99-adbf-419ed44ee28c",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7eafff8-da42-5682-b35b-12c14c39b643",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p2+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f50a5a4c-330a-503a-901e-a2fa855dc909",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc2549b9-e3ad-5fb7-9b16-69f21387a7d5",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec045b35-30b7-5bfd-9ab9-f893f24c54ae",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff4c3c5-44a7-5aa3-bc71-cca092a1c4f9",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fff410f6-ec6a-5363-bed7-c2c320ab1dec",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bbb3e93-74a3-5a50-8c30-e7e5710e9162",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebae6e9d-cecc-58f4-8d16-0411dd0d8017",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:519c5e16-4257-5442-b86b-ed2032153215",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.2-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35dec071-082d-5c26-97b3-182380b5b724",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9603f0b2-e1ac-513a-b309-9ced7782dec4",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05333af6-e5cd-5541-882f-9b324b9a577a",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82eb44e-b89f-5a7e-94c4-b457f404b613",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33347 is a false positive for laravel/framework 8.12.2-p2+tuxcare. false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e0cf2b-769e-5bd0-885d-d440af5eb364",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bba7c47-318d-5205-b300-98422dc2bfa4",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b4d9b10-e09a-5716-9c7d-95f67ae69d38",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.2-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028b5698-ac70-5004-8608-e220c6d7e70c",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab2a2445-ee2c-5dff-bd27-34e0943e275f",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e9cde8-eb5e-5f05-976d-df972ff96777",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.2-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adb1cbec-9127-5132-9b2d-9778ab19b343",
      "id": "CVE-2026-45133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45133 is fixed in version v4.4.45-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17cfc228-6d49-58db-8028-67807a7ad0fd",
      "id": "CVE-2026-45304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45304 is fixed in version v4.4.45-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79c405e-4855-5ae8-beba-dc3712cdbdbc",
      "id": "CVE-2026-45305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45305 is fixed in version v4.4.45-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86070eec-b9a7-5941-a301-743710459a87",
      "id": "CVE-2022-25270",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03539f72-b39a-51ce-a2ba-ec76953d2106",
      "id": "CVE-2022-25271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c64edff5-04cb-5e16-b7a5-7dcf46a69143",
      "id": "CVE-2022-25273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fcb2959-6299-5cf3-97c3-a900fda725d4",
      "id": "CVE-2022-25275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ea70225-0abd-5365-a83e-c7f3ed5bbf8e",
      "id": "CVE-2022-25276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28cf7712-f18f-5094-bc9c-673ba4e37b90",
      "id": "CVE-2022-25277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b0cb14-b425-574c-8505-2ced2d00ba4e",
      "id": "CVE-2022-25278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e58dce-f41f-5a95-9f85-6ad8aee012ad",
      "id": "CVE-2023-5256",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44e34410-e903-5c6f-b3ec-fc819c855d0c",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d2fbe80-8d2e-5729-bcf9-82d1700d11ac",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ac6c949-ab72-5210-9e9b-d29ba63bc09e",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2898f9a5-d816-5a4d-9718-a7a557e1420d",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a053ab1a-fdce-5da8-bd8a-7bd817d6eaa8",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64e9099e-458c-5430-9939-4d400cb91642",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a2bfff5-df98-51c5-bcde-c6378baecd80",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60146035-02d4-5a13-a932-51b224879331",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b30503-03e3-50cb-8eb2-3adf0ff74555",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:167a78a7-0c1f-5890-9302-b7939d525a7c",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3057 affects version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94d86a28-d0f6-5907-99c3-c02c640efc54",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc84d42a-2183-591c-8a83-7d75fd6a6e9b",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc287be-fdbc-515b-a795-1548c021d270",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31a8e407-48f9-5cc1-8954-277d430169e3",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30fce05a-10b6-5692-b563-48767e1273bb",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcb00c07-12cb-56d6-b969-ecf44e056015",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6da4770-2341-5056-835f-33416fa6172e",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a1b7304-f853-5a91-8033-2d8db9ca7723",
      "id": "CVE-2026-45133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45133 affects version v2.8.52-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c780454-ddb3-5218-ad7a-05ecc9996d24",
      "id": "CVE-2026-45304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45304 affects version v2.8.52-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4af1ab8-b025-560a-a095-921e216e6348",
      "id": "CVE-2026-45305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45305 is fixed in version v2.8.52-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4acd3c71-9f35-58c7-8f0d-d626946ad9ba",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5470d2d9-c04a-56a1-ad24-e17e9a4725ec",
      "id": "CVE-2026-45133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45133 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e10597c-cc05-5dc2-8309-23710ca1c37a",
      "id": "CVE-2026-45304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45304 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1983b2a2-8612-5bf4-a30f-07c4571dc603",
      "id": "CVE-2026-45305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45305 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e839b9f-e1cc-5de0-be0f-b5d2151c29f9",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f79072f7-8307-5bb3-b38b-1cb1b3661c0a",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10696673-a588-55f2-a473-82bc5fec6f7a",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.3-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:573f0ffc-3ee6-5b68-bb36-17d6abb8d8cf",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:517322bd-5a83-5964-881c-75b02df60742",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ca31f0f-6d9d-52a3-8e03-433e369e3f8d",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28916c5d-1df7-5b70-92b1-a8d66b39c444",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3dd6c5b-5ab7-5c54-8307-1b8499a18bf1",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed2d932-d767-58f2-8310-12252dc4088b",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.3-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9f2993-0975-5d39-a9f8-043f3d1422e4",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65bebc88-69ef-5f9b-b2f7-3653378ad17c",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:424dd84d-b1e8-5afc-829e-d6b7fb2416e9",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.3-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a2af0a9-441d-5d54-904c-c1c2535c5e97",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55568 is fixed in version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6df26890-e774-5b37-bdc7-f3e3e482810b",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55767 is fixed in version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26d45ce0-aaf7-5123-822e-5ae43eadb580",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59883 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5342448c-e1cc-5614-a576-0263a2cf8c4e",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94pj-82f3-465w affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4908fcab-5696-5bc6-911b-9a07bc473961",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb03bf62-8ce4-525d-84de-160ee64e0fad",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8031ba-150f-5eb1-a219-56497b9a889f",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0ff61e6-78ce-5363-baae-b31df6c9e0ca",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de46e40e-db7a-5317-aff7-e33d11a61ae5",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c280efd9-e83a-581f-a716-4b0f65d994e3",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c2d8dc-2126-5752-93d5-32a8a6aa0796",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77590b62-a678-5889-8260-883bf0c50264",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:140b1551-149c-5f8c-8a93-42fb31e02257",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba6fda5-d71c-5fe3-89a7-2a6898949084",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c142184-6d5f-59f4-924b-551e8adc698e",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab079977-80ef-5f9e-b514-ac4a7e968678",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76ea08ef-a676-5ef9-9f4f-aa90d989a80a",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18103496-3f9d-574d-bbf0-a41fa1357f9a",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:043384c1-c945-57a1-9714-51f9174b2cf3",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90eb8111-94bf-5f65-bcf8-3490f2675724",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae2020c-9b1b-597d-95b7-ee5ea8ffd5a6",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b65549-2811-50c6-b043-244e6664f1af",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf332cf-9692-5baa-9527-7481ed30bdc9",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ce267f-ff17-57ea-a967-dfb390348f57",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2043292-bb00-56cd-9199-c01f396185c2",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39ba151a-51a8-5eb5-938a-e39ed886a6e3",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p5+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f117908-5bf8-5546-bc20-9326d8e393a5",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd9eab3-6939-5432-afd2-282723ebb048",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 9.52.21-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a875ea2d-7aa9-5c6b-8730-385622838105",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 9.52.21-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13457467-c017-5c22-aa61-55cb1f8e85c4",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c49307-9314-5a40-9864-c005e9190b18",
      "id": "GHSA-f57v-q966-7fh6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-f57v-q966-7fh6 is fixed in version 1.11.0-p1+tuxcare of monolog/monolog."
      },
      "affects": [
        {
          "ref": "pkg:composer/monolog/monolog@1.11.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad2cddae-51f5-5fec-8064-8f26190ddb55",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85903c13-b856-5cfe-bb02-06f4f8036fc9",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3243548-fb5c-52ff-945f-73fd2886696f",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b78c5061-d16c-53b3-8970-b5ffa81c2313",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p6+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5fe78b8-7699-536d-8a63-7da5b0e2bbb1",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3dda7f5-ce3e-56ce-9efd-c67a551a951d",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25dc6c7b-5c0b-5d85-8cf5-ab1cbac17c11",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aabc6731-1b6a-5a39-b611-1c9d9f041b96",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:557ca6f0-4f96-57df-b36d-2210c2156314",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cf6c5b7-e417-514e-8642-5bc92d01b2c9",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0219c421-d6e9-5236-9091-85055f94a542",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af4e08aa-2442-50bb-b4e4-b21ebb460cfa",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2c397b4-4b4f-530b-90ce-2428e0081af6",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54fb9c47-4fd3-5ef0-8bee-7c9102bb51f1",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e5000e-ff6d-5757-acd9-0ece37674835",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9144ec33-6756-552e-88a2-39694f1b7f53",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:078aa5f6-dd32-584b-a9cb-aa8b490b9689",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c250e736-8d00-5c86-a1a8-a9d8b282d89e",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71133b7b-03a8-5f59-a0c5-1a708534e288",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bb49a56-6011-52c4-9ea8-0d6f968559ea",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:717a677f-5191-59bb-8bdc-fc1daf414c22",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6af90613-5c89-527e-9835-4cbc160ba294",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30f88063-7c1f-56b1-b9ca-599908a8022a",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb8700d-5973-5cb2-930f-d094643b65af",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de0d1d12-8209-552c-8e38-cfdf97568c34",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18ad230-eb4f-53f4-903c-e039c9afe967",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:135263ff-87ac-5cfa-8f43-07affd99c2dc",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b2810ff-ea0c-5a23-9fb3-dfd4449abc11",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:207910c6-5056-5df0-9f7c-258f5c5cdb9b",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edd0ef62-210f-5166-9f85-98359e6bfe28",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062da20a-ca22-5b93-916d-dc0388d3492c",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8926410-5380-5c2d-b8fa-1af2251ca5dc",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72dd8757-ced4-5c10-ba46-078bb8d0a451",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e74beb31-4428-528b-87d6-7c3d983e8fc6",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09646ced-0dd0-5d0a-8029-3e35de1d33f1",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac1b9157-77da-541f-bbc7-d5b2ee3fadec",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db4f6a7f-7102-5cf5-9e88-9c15d9266541",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bb4e00b-6a08-500b-95cd-4af2142a6e62",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29ea9098-4b8a-5a90-b444-90039bb443ac",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d8a0c3e-b278-5c7a-b108-50916659840d",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee0a08b-7ab1-5328-b378-b388d28c5fab",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21bfce66-1959-53ba-b411-7cbf8a0adb27",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ecde0c-098b-58e3-ab5e-3f92fd37f764",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43336de3-0211-5c6c-ad65-790ffa7e652b",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9537e0f-4f1a-5a38-86f0-6f05be121e67",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56e43b69-aded-5fef-92c0-d848dc4b6963",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cc470dc-d3e7-5c92-b549-fe71d369b15d",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7b8768-bc4b-51f1-8e8d-4e63032b30ad",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d7fb306-8ceb-587e-a546-07e1d38c6c8d",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6106df0-5371-5d48-8927-729404682681",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63da48d7-ae53-548f-8d1e-a28b0511b0bb",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1023075f-a98e-584b-b9ff-debeb32f548e",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49607189-704d-5bbf-a66d-0076338f9756",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e88b78c5-a08d-5923-a94d-e8d1bcdcff66",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:640a1f92-39e5-54ee-ab86-583e6235d60c",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a979354-f2f1-5ca1-99fa-aeb0cd5801a7",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e501dacf-4c3a-5c81-870a-e772138d296b",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ca9e5f6-77da-503c-94b7-7c4b82acf7db",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdccc002-9836-5370-bec9-418254dbce37",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edac6971-a568-54e8-88f5-94d7b7881d43",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8210fc0-2885-53fd-a906-fe47a0e24b51",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1270d883-0203-5659-888b-862fb48eb79b",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11491396-71fa-51db-a9fc-1a2e250a11d9",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9672521-4888-56af-921f-cdcdad9620fc",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d486c64-309b-5413-81e7-19d38dd0f065",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aa43f59-8576-5423-b700-862785d496de",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d04b2c7a-4df0-5732-934b-2d015407e7b2",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p6+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18bffc21-e553-5d78-b146-048105fe7598",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v3.4.47-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173431d9-727b-56ee-9659-bb002ef33de7",
      "id": "CVE-2026-45133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45133 affects version v3.4.47-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55b75cde-fe37-5192-8fb3-582616a7e694",
      "id": "CVE-2026-45304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45304 is fixed in version v3.4.47-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09a2227-2b4d-5eaf-8960-d8effc8f0e82",
      "id": "CVE-2026-45305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45305 is fixed in version v3.4.47-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f4a53a4-8831-5674-98f7-0c4d64e47c69",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v3.4.47-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:012a73ed-c540-510f-bab5-bd6e2d67898a",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0590428f-3be1-5d30-bae7-9c2fb22b555f",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3c36a6a-ddb5-5df1-9d0f-d8f60bc73a11",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606426e6-cbf2-56a9-97b0-724bdeff5f6b",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2a3a25-7a84-5629-8152-6352a8a4c81b",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:434500cf-ee31-5be7-8bdf-922b0bf5c933",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b462831-1d82-54c1-8253-c16679f7d257",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b50f1dd5-fa39-51da-a293-113937a3964d",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5e4f08-3606-515c-bc45-c5d76afde438",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:482d3bdb-be34-5639-8fdd-81f878c944d0",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:593c800d-0c7e-5630-935b-20d8d13783e3",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff86702d-a50f-50ae-ab12-a2afdfad810a",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03d99a87-632e-5949-a021-a611b2e13e68",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3fe1c29-bb05-5144-9324-cd38600f7c4a",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:328dbac3-dc55-54fb-ad1c-f6812e32916a",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e04078ed-2822-56c3-b5e5-10a35985be5c",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a5669b5-21f4-5eee-a7f0-e5270b1d0cea",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:561490ab-ecab-5f40-883d-7c68f49542d6",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40bce37c-7c38-551a-af41-231b121d128f",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4356b10d-ff68-56eb-99e2-509b6caff431",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:453ae9df-dd11-531a-917a-e543e4b86f53",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d49f99-43ce-562b-b084-2e1aeafd8ab7",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd871e77-4463-5ae0-b651-266bedef3610",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efabd6f5-8cb7-5092-9273-be35ef01d4e9",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e68fa75-99a0-5045-ba9c-a7f38a5b2af1",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d371efcb-0805-57b5-8bd5-fa6f0d0f5c42",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16d66f51-9976-5a28-91f8-0478950cbaa2",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0b471b5-52fc-58f9-beaf-f9b7a94fb44e",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9bfa131-4295-579d-a060-091f3bd01669",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9f8f0cd-4817-532b-87dd-bd7ab5a08751",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb28d76-407a-5c19-91b0-4f5f7df965b4",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fee91912-243b-581b-b484-de71c3b0d996",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16567067-b520-5aee-a6f7-24b64fa31375",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:815b82be-7d71-515a-ba3b-e00e361097c8",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f6a720c-4bcc-51f1-bde2-24cfaf59a77a",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:037f81d6-b743-537b-b68f-61d55d196f6a",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cfddd7b-5932-59cd-820d-f86dc457a1f6",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7007e4c1-8d32-5cdc-afc3-9242e67fd544",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa42536e-3b40-57b3-8882-8fa4fbfeb23f",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea54ba08-515c-5060-90f1-a44d28feba00",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3317a30-51db-5fce-b4da-55d9bd92aa77",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2341478d-edaa-56f4-a75a-1f2fcb7eb5db",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87849485-a9a7-5fec-9f0a-2a0184dcf5d7",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 7.30.7-p2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d51962b-3f2d-5c1e-b175-be6f7233d347",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 7.30.7-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc6d1846-1ba4-5529-99e1-30ea49eb79be",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 7.30.7-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54ecb907-7b59-5759-ba86-9a4791b5f1cc",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae78c66-270d-510f-b79f-c1482b97b78c",
      "id": "CVE-2026-45133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45133 is fixed in version v4.4.45-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be353dd2-12c9-543c-951a-70f853e92d01",
      "id": "CVE-2026-45304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45304 affects version v4.4.45-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24625d00-7351-5121-a33a-571324ab8228",
      "id": "CVE-2026-45305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45305 is fixed in version v4.4.45-p1+tuxcare of symfony/yaml."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5838e926-cef5-516e-b6c0-8f856fbe3b22",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 8.83.29-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b018380-6bb0-5a52-8680-badc4d30fd08",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p3+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5e5246-b342-562a-b6ea-62fb226a3bf4",
      "id": "CVE-2024-36610",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-36610 is a false positive for laravel/framework 8.83.29-p3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4f899f8-7b0d-545f-9532-07d6f09ee634",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b08ceae-bb42-52a4-8091-9e4c30f8d8a4",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.83.29-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:849403ca-5fbb-5654-9eba-3a7508e69f5c",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f0cb742-86d5-5a97-81fd-219e32458091",
      "id": "CVE-2015-7809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-7809 does not affect version v2.16.1-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is Twig version 2.16.1, which contains the fix introduced in 1.20.0. The vulnerability allowed remote code execution via the _self variable in templates when Sandbox mode was enabled. The fix adds a type validation check in the displayBlock function that ensures template blocks must be instances of \\Twig\\Template, preventin..."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ceaa5ad-72cc-5df5-b61c-cbd855e91c4a",
      "id": "CVE-2019-9942",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-9942 does not affect version v2.16.1-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 has been fixed in Twig 2.16.1. The target contains the complete mitigation introduced in Twig 2.7.0 that prevents __toString() method calls from bypassing sandbox security policy restrictions."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a0aebd8-adb4-52e1-a33c-b5505dd4b962",
      "id": "CVE-2024-51754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51754 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c030c400-9754-52fd-8dfb-ba9dc64a8b79",
      "id": "CVE-2024-51755",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51755 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d382ccb-fb8c-5d54-8040-de3a99fd632a",
      "id": "CVE-2026-24425",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24425 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe3658cd-8965-5b00-9fc9-64149a53ea34",
      "id": "CVE-2026-46628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46628 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10393b78-ed14-5412-bb0f-ddac629d59bd",
      "id": "CVE-2026-46633",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46633 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b6b7bc-a4ac-5859-ba2d-a9b9331dd1a5",
      "id": "CVE-2026-46635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46635 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35b894cc-c5c1-5374-bf59-c350d619ab10",
      "id": "CVE-2026-46638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46638 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00c7ee7-a695-58ee-9183-74db0a7d7ed8",
      "id": "CVE-2026-47732",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47732 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad78cdbd-a825-5eeb-8508-0ecf2bd0eee2",
      "id": "CVE-2026-48805",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48805 does not affect version v2.16.1-p1+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48805 describes a sandbox bypass in Twig v3.26.0 where deprecated wrapper functions in src/Resources/core.php fail to forward sandbox state to refactored CoreExtension class methods. Target v2.16.1 uses a completely different architecture where the vulnerable delegation pattern does not exist. The functions twig_array_some() and twig_array_every() don't exist in v2.16.1, and twig_check..."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8562ca-aeea-5d88-9fb3-00923e00b7a9",
      "id": "CVE-2026-48806",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48806 affects version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c2e99dc-1934-5b58-aa45-8d6e19bae2c9",
      "id": "CVE-2026-48807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48807 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22d82b1c-4a7f-59dd-9560-cc382d5f1012",
      "id": "CVE-2026-48808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48808 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94df886b-90bd-570b-9517-01acb9f9438d",
      "id": "CVE-2026-49981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49981 is fixed in version v2.16.1-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:becee7b9-308b-5204-a773-22733346ffab",
      "id": "CVE-2022-29248",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29248 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e6c630-3b64-5fc8-b59f-97cec53cf2ed",
      "id": "CVE-2022-31042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542a5204-5fcf-514c-acee-8337ef862450",
      "id": "CVE-2022-31043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31043 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce16c33b-7622-5435-87aa-7dba580ad7ae",
      "id": "CVE-2022-31090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31090 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a2896eb-9ccd-5d63-a15f-703acf9155b4",
      "id": "CVE-2022-31091",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31091 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc36379-053b-58e5-b88a-156a61eecf30",
      "id": "CVE-2024-28859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28859 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f75f119-147d-5aeb-a1ab-e80a1c6d38f8",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55568 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce67120-aaab-59f0-b412-ec1e6c22a46c",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55767 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ed9a574-151f-5465-9280-ea26ec62aa6a",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59883 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e93f163-57b0-517d-b9bd-3f242591f535",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8e6c2f-eb1c-583a-bc58-9255a0f6921f",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7f69bbe-8224-5172-982b-93a129307bfb",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b6be2f-76e8-549f-a7de-23872083b5c4",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f13d214-cfaa-521c-b5eb-c52c1c6f7b65",
      "id": "CVE-2022-24775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24775 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91a7897-0a04-5dec-a660-4e6c18b43e54",
      "id": "CVE-2023-29197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-29197 does not affect version 1.4.2-p1+tuxcare of guzzlehttp/psr7. Version 1.4.2 is not vulnerable. Summary: CVE-2023-29197 does NOT affect version 1.4.2. The vulnerable code (header validation regex without /D modifier) was introduced ~3 years AFTER this version (in commit 092dbc2 on 2020-01-09, first appearing in version 2.0.0). Version 1.4.2 predates the introduction of the assertHeader() and assertValue() validation methods entirely. Since the vulnerable code pattern was never present in this version, it is not vulnerable to this specific CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce7702a-414d-5371-b413-0b8de79eec75",
      "id": "CVE-2026-48998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48998 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d9e051-ad82-51b4-9166-cd3f542c444a",
      "id": "CVE-2026-49214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49214 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e90a7ce-c94e-56ef-8158-3e523d0e3641",
      "id": "CVE-2026-55766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55766 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:158b2abb-2747-5e51-ac2b-c81b0997dab2",
      "id": "CVE-2026-59882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59882 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d81f9724-f43b-50a6-8f60-4c745915a5ef",
      "id": "CVE-2015-7809",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-7809 does not affect version v2.15.6-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is running Twig 2.15.6, which is significantly newer than the vulnerable versions. The security fix that prevents arbitrary code execution via the _self variable in Sandbox mode is present in the target code at src/Template.php lines 175-178, with explicit documentation ('avoid RCEs when sandbox is enabled') and test coverage."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a8d4282-2610-5357-831a-fc699e2cc5ad",
      "id": "CVE-2019-9942",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-9942 does not affect version v2.15.6-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 was fixed in Twig version 2.7.0 (released 2019-03-12). The target version 2.15.6 (released 2023-11-21) already contains the complete fix. The vulnerability allowed calling __toString() on objects in sandbox mode even when not allowed by the security policy. The fix introduces ensureToStringAllowed() method and CheckToStringNode wrapping mechanism that validates all implicit __toSt..."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:653b3914-0647-5120-88c0-6ffc187113c0",
      "id": "CVE-2024-45411",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45411 is fixed in version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1474dc45-821e-533d-9912-9feed780a3b5",
      "id": "CVE-2024-51754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-51754 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4724bad-17ed-5ac4-ad44-d728fef00ec5",
      "id": "CVE-2024-51755",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-51755 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60921dba-820e-5fe3-bd94-c8cd92d37d74",
      "id": "CVE-2026-46628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46628 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4fcfb8-211b-525a-9c09-596f6cdabc10",
      "id": "CVE-2026-46633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46633 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed48bb1c-4712-5d13-aa48-cdca0e987ab2",
      "id": "CVE-2026-46635",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46635 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fded66f1-956e-52b2-8e3c-5e458b563579",
      "id": "CVE-2026-46638",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46638 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a32b455-e829-5954-b79f-25bb92bbf4fd",
      "id": "CVE-2026-47732",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47732 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1af9ccd-2d59-5e34-b757-1fe394d47568",
      "id": "CVE-2026-48805",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48805 does not affect version v2.15.6-p1+tuxcare of twig/twig. not_affected \u2014 Twig v2.15.6 is not affected by CVE-2026-48805. The vulnerability exists only in Twig 3.26.0+ where architectural changes introduced deprecated wrapper functions in src/Resources/core.php that fail to forward sandbox state to CoreExtension methods. This architectural pattern does not exist in v2.15.6, which uses a different implementation where sandbox enforcement is correctly handled."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98f29586-d48e-5f77-b08a-6d6f3ded9399",
      "id": "CVE-2026-48806",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48806 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e1e0fdf-b3d1-516c-84cb-3904835f1c54",
      "id": "CVE-2026-48807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48807 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77262c09-3a61-5204-9bba-dc5446c78984",
      "id": "CVE-2026-48808",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48808 does not affect version v2.15.6-p1+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48808 does not affect Twig 2.15.6 because it specifically targets a vulnerability in sandboxing enabled through SourcePolicyInterface, which does not exist in this version. The target uses a fundamentally different architecture predating the SourcePolicyInterface feature."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f26fee-93c2-5659-87e0-f6cd4ed4b678",
      "id": "CVE-2026-49981",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49981 affects version v2.15.6-p1+tuxcare of twig/twig."
      },
      "affects": [
        {
          "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d635bc-f329-58e1-8502-16086211672e",
      "id": "CVE-2026-48998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48998 is fixed in version 1.9.1-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb90ab65-1cec-5b59-bb3b-bed536307013",
      "id": "CVE-2026-49214",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49214 is fixed in version 1.9.1-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2fa7f3f-3892-5f30-96aa-acad4b07cbce",
      "id": "CVE-2026-55766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55766 is fixed in version 1.9.1-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f61e68a-af68-5890-8eb1-02a5dc2e367e",
      "id": "CVE-2026-59882",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59882 affects version 1.9.1-p1+tuxcare of guzzlehttp/psr7."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0972ecb7-8ee3-5c51-9fa1-42001d558b41",
      "id": "CVE-2023-51651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-51651 is fixed in version 3.263.4-p3+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34874c4-b09b-5380-ba28-9dd3777588d8",
      "id": "CVE-2025-14761",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14761 is fixed in version 3.263.4-p3+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe578e7-5a80-5d2f-b9ae-b8f67ef70961",
      "id": "GHSA-27qh-8cxx-2cr5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-27qh-8cxx-2cr5 is fixed in version 3.263.4-p3+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a76b3b-1d18-529d-b488-bdc7c5d2a4fe",
      "id": "CVE-2015-8379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8379 is fixed in version 2.10.24-p2+tuxcare of cakephp/cakephp."
      },
      "affects": [
        {
          "ref": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04a0682a-128c-5d53-8b0b-488d27458f21",
      "id": "CVE-2020-15400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-15400 is fixed in version 2.10.24-p2+tuxcare of cakephp/cakephp."
      },
      "affects": [
        {
          "ref": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5d8a387-2213-52b1-ad76-37c34faef692",
      "id": "CVE-2026-48820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48820 is fixed in version 2.10.24-p2+tuxcare of cakephp/cakephp."
      },
      "affects": [
        {
          "ref": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a69a94b-4d4a-5181-93b6-f2c1a01b933e",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe84a6c-a156-53c9-be6a-c0add4671647",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f5ddb79-c759-5d2b-98fd-9c99e1485b72",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91e9f6e-7f77-557d-97c9-b22a2053cf5c",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p5+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddef341-d562-5c0f-97b1-df059f71274f",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49d8f27-97b9-587b-9961-420b1b45df20",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b30caea-f7b0-5c40-8fc2-60f96ec6fbf2",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:269a7166-0e4f-5862-9dd7-5b9e1c19d1ac",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c9f09dd-0f9d-55aa-b3f2-2d01e9b80798",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:965b834e-9cde-5424-991a-f4d50b1eb212",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073dfc3d-1105-5a8f-a2eb-211d6024229e",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a2da6f2-792f-527e-bb40-f8616b5928ab",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2b0e01-f742-58bb-9f82-7b3faef79563",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d02134-d6f9-5307-9dfd-bbd57a57a551",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d44f8665-7007-5466-bdb6-fae174e52a16",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c450b217-ba90-5447-9a6b-144cb50d872a",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a81e2d7-ed02-5a97-b30e-9c8aace50809",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028729fe-5b7f-5b29-9b06-43af7273ea38",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:923e89ed-af6c-55e2-bd07-96eaddde59d7",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0db59fe7-11b6-50fb-b155-99c564cde6b4",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b64dca-94cf-5c4b-a83c-0ad3e31216b8",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22dd8c3-853b-5205-a2a1-6211573150f6",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da8b2514-c604-5956-ab30-9656d3e2ec5d",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be5125b-6603-5b40-9b79-59787d19b01e",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:162017fa-10a2-5123-830e-c327fd677617",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:733925d2-dabf-5f02-9449-134b9df251f0",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37601131-7245-5881-adc0-8a0bcfdd3241",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b787e65a-2509-5647-b052-8d924d492acb",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96486b3c-e190-56d9-b5ee-fdb3d8d9f043",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba63d51-1f07-5d2f-81d5-066276c64e08",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40292e75-c2e8-54dd-98de-5b880e55c58b",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9461e44c-f6c4-5d82-91c0-38480cb77683",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c71a535f-5522-5888-8156-36e090dfb60a",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86f2a15-203c-573e-a129-df582c5eb272",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ced1ee14-4f23-57bf-be73-30cabdebfb87",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a43ce4d4-918e-5042-83e5-8e357d0214d9",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bccd797-ad9a-53f5-b04e-fdf0146c7396",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1addcb45-406d-5e38-8e9d-2cfec0654ad7",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d10c525-f589-550c-8d01-4e3a16cb08d2",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04bb448-16c2-5ffc-b680-ed260e2ca4a5",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c56abd1d-15f8-5b96-84b8-059a3b9a78e1",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2a578a2-05ce-5f3d-80b0-c756d858f377",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34061ace-8cae-53cb-bb00-dc15a3c58a22",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43406ad6-ada4-5305-9605-40c3e0753bb5",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7599e21e-c831-54b1-a7dc-1f237dfeea61",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f173a0eb-5b27-540e-8e05-212c8979fa74",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ffcee44-3b79-5132-8ad8-c2fd96f29811",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e4c946e-05a5-5229-91e9-2dd015152493",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c3ff2e-85ad-50f7-9f55-32749a8103ab",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df2cd2b-29b4-58e7-8f79-87795157c648",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed2da36-922e-57b6-ad75-3c07153e9c71",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dbf7718-7d2e-5825-837b-86805e677417",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d643299b-3b50-5a65-8e2a-d1ca9c606d31",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc83b36-a78d-5c21-afd3-70c0353279f7",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c67328-ffdc-53cb-a2ed-c142973bd345",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37767d6e-7c59-5c95-9884-8904ecc0fce8",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5620671-2c31-5970-8ed5-ae1fbd527d13",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:508704bf-600c-52f2-b4e7-9d7ac97f40fc",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55790 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c21ccc5-de34-57b0-ae1c-7fbfa1304ca2",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5072992c-bf52-5f04-a336-f7571ef70f0c",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca7bd830-08ae-57aa-9cd0-f9d8e1052fe8",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5cdfb53-d909-58e0-beda-cd1b4ea4393d",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9fd3b11-68fe-5e83-ba67-c8660366eab6",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ed337b-24da-582e-8b2e-d87eea1abe00",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ad33ea-39fd-5898-9620-f067fcbb8fa1",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f3cad2-50eb-54cf-9aee-28c8eeb8bef4",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e0dcf8-e1cc-58b4-a764-ae29f3ee443f",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96f1a299-7ee4-5f8b-adfa-e38ef461317b",
      "id": "CVE-2025-54370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54370 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fac22a-e40b-5392-9068-f645c0fa3bfa",
      "id": "CVE-2026-34084",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34084 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bb596f2-b9a0-5623-9d27-d1793f85569c",
      "id": "CVE-2026-35453",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-35453 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89132952-570b-5ebf-99da-6e4cf901db24",
      "id": "CVE-2026-40296",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40296 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41cd101c-49f7-5198-94d6-009a1d9768b3",
      "id": "CVE-2026-40863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40863 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7b6614d-6914-5ea0-b51a-3e657fb38bdd",
      "id": "CVE-2026-40902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40902 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dcdf5b5-2b33-555c-b629-3ba4f1846cf7",
      "id": "CVE-2026-59931",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59931 does not affect version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet. not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do..."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c91d6bf0-250e-58bc-8ea1-a3e7d02ddb40",
      "id": "CVE-2026-59932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59932 affects version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bdd5424-69ad-5283-b65e-bbaa62f061fb",
      "id": "CVE-2026-59933",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59933 affects version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e724f608-acb3-52d2-8d03-d7f2cf6425bd",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09a1b8d2-c279-55f4-a160-34e6f7f711b5",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29cf3ad6-fbbe-5c10-9ccb-9440d89de937",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7599a271-e8a0-5001-9256-d9c0065b3aa2",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bc3fb42-ed48-5e89-b413-7bb24bb3982f",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f818aa-6854-5a83-83d3-283eb7fd116e",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3303543a-c6fa-5a31-803b-ad0f9763d7d3",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4856bd7e-28d2-5fc7-8d66-10900a7f73b4",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d04fb2d-d3b2-5ce3-8c87-402def57fcbb",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b841a71-0cdf-5eef-a517-0866268d83ec",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c0536cc-210e-5c9b-94e7-220fc9a985dc",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b638c3ae-5000-5636-beea-ed8650344aea",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c75e6d6-d0a6-5a84-b5a3-9c0b1c53a51c",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e51c4f-dbff-54e5-b0c7-61f5b83c4d20",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39a43c3-68bd-591e-aaa5-7216179fd7e3",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af7ac30-aa0a-50d2-a92f-6acd4b7d9d92",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab853414-47ab-5a6d-9fe5-4039028d1f45",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8436284-905f-5ed4-b230-7cd38a06f65b",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13825afa-e951-58af-9715-75314b6bd69a",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p4+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c879e995-0426-5d41-99a1-fb308f21e6b2",
      "id": "CVE-2026-45075",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45075 is fixed in version v7.4.10-p1+tuxcare of symfony/http-kernel."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-kernel@v7.4.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ce45ced-5be5-54ea-ad74-65a23154eff9",
      "id": "CVE-2021-3007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3007 is fixed in version 2.5.6-p1+tuxcare of laminas/laminas-http."
      },
      "affects": [
        {
          "ref": "pkg:composer/laminas/laminas-http@2.5.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b8d09b3-4200-58cb-a4c3-96b9451f3c9a",
      "id": "CVE-2026-45068",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45068 is fixed in version v6.4.34-p1+tuxcare of symfony/mailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mailer@v6.4.34-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2645d5bd-8a44-59e4-8350-3866514f58c0",
      "id": "AIKIDO-2024-10189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10189 is fixed in version 9.12.4-p2+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c35eb6-90d6-52af-aea2-3d1b2452e5f7",
      "id": "CVE-2026-48555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48555 affects version 9.12.4-p2+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a479cc-0893-53b4-af5b-35ff55408755",
      "id": "CVE-2026-48557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48557 is fixed in version 9.12.4-p2+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94cceb02-ad04-5c93-a975-a67608e9fdba",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v4.4.44-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c993cbe-e6ce-5d27-846c-c8587a5e735c",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v4.4.44-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2d81a91-96fe-5280-85a2-007a81a29a02",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v3.4.47-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54ebfa8-03b9-575e-a129-27b2205d89b4",
      "id": "CVE-2026-45304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45304 is fixed in version v3.4.47-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da2f26f3-7d92-59ca-ab59-c3121b90fa5a",
      "id": "CVE-2026-45305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45305 is fixed in version v3.4.47-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b0155f7-d964-5767-bad4-54059fe0d5bf",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v3.4.47-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c1c6bac-7f54-50b0-90f1-27a315eeda70",
      "id": "CVE-2022-29248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29248 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a171cca6-2446-598f-b359-6679e741d870",
      "id": "CVE-2022-31042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d94d811-313b-57c0-82b9-23b18e53c2ef",
      "id": "CVE-2022-31043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31043 is fixed in version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8c90c16-c0f1-5fdb-88e0-a007a224d908",
      "id": "CVE-2022-31090",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-31090 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbad3e57-dc61-5e00-813b-b3a40ce715d8",
      "id": "CVE-2022-31091",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-31091 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a25da969-b833-57c0-bf2a-38f2e501db4c",
      "id": "CVE-2024-28859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28859 is fixed in version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15eb4de9-3182-54bc-bfdf-7252319ea58c",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55568 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a15a42-b332-5691-8152-7fb2ef4e379b",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55767 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fcf2048-2794-5f51-84e7-f29986462a83",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59883 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c77f0b8d-a5d1-52de-8d9c-d8be52113c60",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d23a221c-8768-538c-8ae9-2dfc0ba20ef5",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f24fd8f-e876-5596-8a3c-5882af50257e",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f962282d-80a5-50f6-b487-e7724bbdf31e",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5dcbc25-423b-52f8-a9c5-078ec403452a",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55568 is fixed in version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6740896-d41b-5a8f-8033-aff5976cb70a",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55767 is fixed in version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32f91c22-2fdc-57e9-82dc-c6c073942526",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59883 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc4ba5b-f081-5ce8-9108-373188c38c0f",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94pj-82f3-465w affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e035fdb9-d086-5bfa-af10-d2ead3e7fa1c",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda5ad1b-9827-5e3b-be70-7069738c26cf",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e93e09-7eb5-54f8-bc52-b22eba1a0ac4",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa40436-2e30-5dad-a7ce-829c50855a0a",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa38883c-8907-5872-9410-023f30f3baf6",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 9.52.21-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606df55d-0a83-5677-8ad0-49698b8156a6",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 9.52.21-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3266a2e-b0a0-59f4-880e-b0241372f215",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16e4f125-307c-5f80-a1a4-2177f8dacaa3",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.48.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37dc75bf-ba3d-5c3a-98ab-c9cc7b616a5d",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.48.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.48.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 10.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e840a2e0-6142-5e72-b98b-6e962550c8ae",
      "id": "AIKIDO-2024-10189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10189 is fixed in version 10.15.0-p2+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb4b7f6b-213f-584f-981c-f2a7d163348c",
      "id": "CVE-2026-48555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48555 affects version 10.15.0-p2+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34aa6e85-b6ae-50a7-bac8-4bcc295a3937",
      "id": "CVE-2026-48557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48557 is fixed in version 10.15.0-p2+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3305d2be-7288-5544-a8f1-c246ec4f20f6",
      "id": "CVE-2026-45067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45067 is fixed in version v5.4.45-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4eddaef-a23a-55e0-9412-3b42fe509f40",
      "id": "CVE-2026-45070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45070 is fixed in version v5.4.45-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc81ae42-db95-5221-9293-39a8cf450b64",
      "id": "CVE-2022-29248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29248 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0098ef-a997-58ec-afae-3f858c09b3e2",
      "id": "CVE-2022-31042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dfd9729-239a-5fc4-9900-9b3fc2d22730",
      "id": "CVE-2022-31043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-31043 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ebd7946-724a-52b1-8ad9-a28814f43dd4",
      "id": "CVE-2022-31090",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-31090 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5a5f996-2c78-5bed-aaec-d5e003ccf48e",
      "id": "CVE-2022-31091",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-31091 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60a3eaf3-491a-55c1-8cde-8c9a34702d45",
      "id": "CVE-2024-28859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28859 is fixed in version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20fbcf81-36ce-57e6-a342-696fdb55c683",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55568 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9400ee-ec99-5be4-a97b-7b8168ae553d",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55767 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3de22222-dc94-52e8-9f38-74f9338e622e",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59883 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0a43641-985a-5193-b661-3584cbc589ad",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:928c0103-ec92-5cee-9ba3-a5cff76fb124",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26a73f91-0328-53ed-adaa-96f8344ee3ea",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:396224cc-c03c-5960-81f4-d47b1580d245",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:662926d6-e0c7-5e70-a6d4-bef8273c4c21",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v6.4.37-p2+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13e536ef-1c36-5b1c-a197-f02b99605eb1",
      "id": "CVE-2026-45067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45067 is fixed in version v6.4.37-p2+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec538ebe-6323-5b90-b517-c086231f8f97",
      "id": "CVE-2026-45070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45070 is fixed in version v6.4.37-p2+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfa63336-2d2b-5554-b950-9b7f88d9c1eb",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v6.4.37-p2+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9952af62-68a6-53f5-b14d-d18f6d8dae6e",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737a5058-d2a1-5832-bd29-dcc2ecd0cd69",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:add85e9e-d4ac-562c-886b-7d0306b40df6",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:854f8a18-1fcb-58a3-8d06-d4759722ab9d",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b5d3f14-d35a-578e-9c25-b8308e481902",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c9bf86-e8ee-50a7-88fc-a11efd8f778b",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f572a4a2-4638-5b9c-8ba8-404b5120d091",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb8410c-d7af-50ae-9d9f-86d301a83c3c",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f09b8e5-2553-5ed1-903f-ea92a97352b9",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eaf4e4f-a593-5965-9ee9-e996eed017fa",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad282152-56db-5789-9ccb-07c500aa91d1",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3cd3db3-b6a1-5cd7-bd61-890913df680d",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61ac86c-8814-58a0-befa-2aa20f339e41",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1299e85d-36d3-54c6-8ac3-803e8e6cdea4",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bdd02bd-4844-5c8d-9e9c-0f1d62b1d6af",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c8a10c8-1e1d-5212-a256-d474108a574f",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c25bad10-861e-55da-9b38-da7f211ac240",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613e0c3e-b20a-533a-836b-bd64131f6e8b",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1728fc40-5842-5399-a1c4-d580c4099bec",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ebc794-aa54-50b3-bd10-64c54535f97c",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6513a085-2632-5a8f-a64d-2e24e8441d95",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:640efa9d-43dc-5800-96ba-1a708df14537",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec381310-9bd0-5b0e-86f0-74cf180c83f4",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b783fb2a-6a22-50e6-b1e9-900363b44941",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43e00ef1-44a8-5dbe-8176-14a8a0138d6a",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:662fe288-d3d1-508a-9ef4-d3d6158e0ef2",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aeda6d7-93b4-5f6f-9f7f-d52e3d6541c7",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1084cbb-dd1e-5963-9343-eabb13736d7a",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f84c0117-919c-50d4-861d-54e12b813668",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36c8d5f5-059a-5986-932a-2460772fd316",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e024a4b6-e6c8-5ea2-8fe0-1d146175189d",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:632e1ba7-4cee-55a8-b8ec-c11d8fbf33ac",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79b218e-22fb-5f0b-a03b-b9d242546b29",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25496 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:009b9271-18c8-5dcc-82c6-e1373651f0d3",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e57f28f4-930a-5529-be2a-3df21a4cffa2",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d524d6d3-0832-5ad7-9711-4bb66a7b5249",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:993387d8-4ba7-5829-9c3e-d9c33f0b725d",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c10dcf-56d1-5b77-824a-9ae863bd774c",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41b0e3f6-ebe1-5ea4-a044-ae90bfaaf654",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c0d167a-f926-532b-ae7c-380d6ff6b474",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28025641-80a6-5bf1-af0d-bc7dc1341d7e",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e69a92bb-922e-5082-9d85-5eb1a6e0929f",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4745df30-bb7c-5ea3-9f7c-045bb4fa9ebe",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc55bf3d-a8b7-510e-8785-628000384d34",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2848d7a1-09e3-5bfc-8462-ebafeac3ee37",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9030d7eb-848b-5d1f-9b36-89238c98835a",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c223f447-e9da-575f-8e6d-b65f48ae3e65",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaccea07-be36-5434-9661-92fe2ddc2b8f",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173248c6-1fb7-5e07-bd86-0d175e9e9f61",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d0d546e-8fc4-5b2c-8d7b-f4a44e766667",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e96610d2-c080-5f1b-9bc6-6fb2975c320e",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c8d7623-5615-554c-bcb1-8cde76f3bb07",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2757d17e-0d69-57ae-a5cd-e26554c6941b",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028e5740-01f6-59fb-a2cc-5928c0b57a3f",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abffe984-9245-59c4-a4b4-2d945eab2bbf",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ef0c59-72ba-5c52-8bab-6f0747dd5ff7",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:178c688d-47da-5fe7-95fc-f732630b4a54",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7951efe-b9d9-5413-9dea-b08b55de408b",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55790 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c70c253b-ceb8-50b6-be5b-e77dae75f8a9",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c9a104-6f30-5633-89fa-8f52c56aeba3",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af982fec-83a5-51a3-8405-8caf34f7fb93",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a78ee918-3d8a-5b07-a7ca-1d36ad15815b",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79245e4c-d2bc-5779-b853-0c7437399a9d",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f2c3952-83e8-590d-87ae-1bf7a1365422",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a905bb1-a859-5b0d-9c59-625cc5ee496d",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961de65a-af09-5d49-a067-9c1aea77f92b",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13416e78-2129-5d31-b9f9-1faa3a0f09b6",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p4+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5c56559-4720-52fa-aa5c-1d66e316a6c2",
      "id": "CVE-2021-30130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-30130 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adc08cb-e5f4-5831-80af-a06e6fd70dfe",
      "id": "CVE-2023-52892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-52892 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:390a3e68-bf05-5cdf-aaa4-61f1efc9f684",
      "id": "CVE-2024-27354",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27354 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1635bfc1-bed7-5cbd-adc2-e2d023ae7189",
      "id": "CVE-2024-27355",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-27355 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aabdf849-55aa-5e2b-bea8-4dfa83df8e15",
      "id": "CVE-2026-32935",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32935 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51ef5ab-15e5-5381-8fcc-04fe63ea20e7",
      "id": "CVE-2026-40194",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40194 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b90fe98f-b164-5a54-9891-7c1752fed2a7",
      "id": "CVE-2026-44167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44167 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3872b129-6b02-5543-b2ff-cec6c1b68523",
      "id": "CVE-2026-55599",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55599 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639e0852-50f4-5501-b2e2-51e881e41355",
      "id": "GHSA-m557-wrgg-6rp4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m557-wrgg-6rp4 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6540cdbd-b251-5b35-986f-36219ecdada5",
      "id": "CVE-2022-24894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24894 is fixed in version v3.4.49-p1+tuxcare of symfony/http-kernel."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-kernel@v3.4.49-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7fdea0d-f7e3-506a-b6b0-56ce0d56c23a",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 10.48.28-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0cdd7fd-d0f4-5bae-9e3b-8fb3b6c341d2",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.48.28-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f03c139-732a-5ff6-8608-0c5afca53558",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.48.28-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.48.28 does not contain the vulnerable code path. The vulnerability (GHSA-crmm-hgp2-wgrp) affects Laravel 11+'s LocalFilesystemAdapter class, which was introduced in Laravel 11 and does not exist in Laravel 10. Laravel 10 uses a delegating architecture where FilesystemAdapter throws RuntimeException for local filesystem temporary URLs rather than implementing them."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe9d91b-9df2-5f07-a5aa-c31c0fbebedb",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v5.4.48-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79cc13f1-810a-5490-ad72-7c98c71091ed",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v5.4.48-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64091aa-9802-5780-a521-595eb0b1dca7",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 10.50.2-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:143a58cf-7f1d-5aba-9868-16476f3bb7a8",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.50.2-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c50b4bf-0d5f-5dc4-8d93-2f5129f84de7",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.50.2-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9d0af64-ec76-5aff-ad29-6a922acbd39f",
      "id": "CVE-2021-3007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3007 is fixed in version 2.5.6-p2+tuxcare of zendframework/zend-http."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c4ca67-3030-577c-9c28-affd82569592",
      "id": "GHSA-cg8w-5jrc-675g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-cg8w-5jrc-675g is fixed in version 2.5.6-p2+tuxcare of zendframework/zend-http."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e8c9ecd-1ff5-5e19-a342-676ea440d889",
      "id": "GHSA-f6p5-76fp-m248",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-f6p5-76fp-m248 does not affect version 2.5.6-p2+tuxcare of zendframework/zend-http. already_fixed \u2014 The target repository has already been patched. The vulnerability (GHSA-f6p5-76fp-m248 / ZF2018-01) was fixed in commit 80b11a4c9a711ec50bca8892af91f809a2d1b958 ('Backport GHSA-cg8w-5jrc-675g to 2.5.6') dated 2026-06-24, which removed the code that unconditionally reads X-Rewrite-Url and X-Original-Url headers. The fix is identical to the upstream patch."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:390862d8-4dc7-5ebc-8a09-1e44d31446f7",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 11.44.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09810cd8-c140-5a04-bed0-a46143e3390e",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-24765 does not affect version 11.44.0-p2+tuxcare of laravel/framework. CVE-2026-24765 pertains to phpunit, not laravel/framework. Tracked on the phpunit VPV."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f8f4abb-f86d-5a46-92c5-a12f0b1c0a35",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 11.44.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3487b1d-d60b-5fc2-b92d-f29182b005fd",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp is fixed in version 11.44.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1396ad6-488e-54fc-867c-c2967f48e25e",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 12.58.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33f44249-4ee7-595f-acb8-257a9baeb565",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 12.58.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3174f4-f83c-5fbd-a6a1-3f7c7ad57608",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 12.58.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5493fca-2177-5932-ba4a-6fb79d1e4982",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 11.51.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc989935-8a40-5d1d-8dfc-a08a902ffc24",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 11.51.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2f31fcb-59da-5ead-a63f-b8809148b3ec",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp is fixed in version 11.51.0-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6198523f-beb0-5bb7-9d25-b39f174aab5f",
      "id": "CVE-2026-45068",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45068 is fixed in version v7.4.8-p1+tuxcare of symfony/mailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mailer@v7.4.8-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c84ab930-024e-50e5-b643-43c7a309a780",
      "id": "CVE-2021-3007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3007 is fixed in version 2.4.13-p1+tuxcare of zendframework/zendframework."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ec9def-5524-53cc-a990-92ac65a1472b",
      "id": "GHSA-fh7r-58q4-6387",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-fh7r-58q4-6387 affects version 2.4.13-p1+tuxcare of zendframework/zendframework."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:deab1e3d-c95c-532e-9764-28a09f0b0b27",
      "id": "GHSA-gff2-p6vm-3p8g",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-gff2-p6vm-3p8g does not affect version 2.4.13-p1+tuxcare of zendframework/zendframework. GHSA-gff2-p6vm-3p8g is fixed in 2.4.11 (per https://github.com/advisories/GHSA-gff2-p6vm-3p8g); this VPV targets 2.4.13 which already includes the fix \u2014 not affected."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aef7dcc0-a8bd-537b-b574-29250c9bdc70",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v7.4.9-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eeba439-3583-58de-a596-e8569149c281",
      "id": "CVE-2026-45067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45067 is fixed in version v7.4.9-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99f55a5-652a-5c3d-b17d-360e29bacb3b",
      "id": "CVE-2026-45070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45070 is fixed in version v7.4.9-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6a20dc3-6d10-59c3-a4bd-37ba9f3f1ebc",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v7.4.9-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08e2715a-8c00-5949-8176-6a87f3e49511",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v6.4.37-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a43bb32-37c0-5b65-8316-c37da1a1b8cf",
      "id": "CVE-2026-45067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45067 is fixed in version v6.4.37-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2826a295-5f70-59fa-93bd-1bc31d246271",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v6.4.37-p1+tuxcare of symfony/routing."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:743a3737-9afa-5794-aa23-0a9b230975bb",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v7.4.9-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0099cd73-09fb-54f3-8f81-0196450032c3",
      "id": "CVE-2026-45067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45067 is fixed in version v7.4.9-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac4aef86-aadf-54ca-8dce-fd3b21f8f076",
      "id": "CVE-2026-45070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45070 is fixed in version v7.4.9-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b94b62-f497-5343-b5b3-ca7ef998e3e9",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v7.4.9-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e51f1bbc-bdb5-56a2-ab97-3ab1c028139c",
      "id": "CVE-2026-45065",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45065 is fixed in version v6.4.37-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6753fb29-9d94-5c2e-a58d-b473dcd5e933",
      "id": "CVE-2026-45067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45067 is fixed in version v6.4.37-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:795f91d2-47f4-54d5-8f43-5753bb6df512",
      "id": "CVE-2026-45070",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45070 affects version v6.4.37-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d4bb79a-e416-552c-8645-5acbac61b08c",
      "id": "CVE-2026-48784",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48784 is fixed in version v6.4.37-p1+tuxcare of symfony/mime."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea51983-66a6-57e1-b4c2-355890a0ac5f",
      "id": "CVE-2023-29530",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-29530 is fixed in version 2.22.0-p1+tuxcare of laminas/laminas-diactoros."
      },
      "affects": [
        {
          "ref": "pkg:composer/laminas/laminas-diactoros@2.22.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8847b7b-4707-5cb9-998e-c69c86f8c8de",
      "id": "CVE-2023-51651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-51651 is fixed in version 3.263.4-p2+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ecf3e00-81c3-5f20-8684-e059e769b119",
      "id": "CVE-2025-14761",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14761 affects version 3.263.4-p2+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6033acde-674f-5098-9b55-6d7fca52871f",
      "id": "GHSA-27qh-8cxx-2cr5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-27qh-8cxx-2cr5 is fixed in version 3.263.4-p2+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c6706e5-9613-5a91-b81e-1908494b957b",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df95f1b8-735d-51e3-b68f-9647f8d72b50",
      "id": "CVE-2019-9081",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2019-9081 is a false positive for laravel/framework 5.8.38-p4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4efe285-d0fb-5fc8-ab9a-cab51f3a9dfb",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:152e3d25-edcf-5ec3-8f58-d687c10019ed",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.8.38-p4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b0ebd31-6609-5901-a26c-de74539fec3e",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:324213c6-baf4-55e7-846f-7acdaab06f71",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2de46681-b021-5169-88c1-40a1ec7bf084",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479bf41c-1528-50ce-a076-922523b86326",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58102e50-a84a-564d-9dfd-fb608ec01b5e",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fea781c-a6d9-52f0-be70-113cc477e88e",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99439500-dad8-501a-b17a-c87f4d0d8346",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:338875ff-ae61-59eb-8da5-451d453b758c",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33cb128f-2bf0-50ff-a466-530f26d3aa9d",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 10.48.28-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:746447ad-c4c3-5b01-87fc-6cc1d51aaf49",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 10.48.28-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd9b73c7-400b-5527-add8-44cb51db7515",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.48.28-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.48.28 does not contain the vulnerable code path. The vulnerability (GHSA-crmm-hgp2-wgrp) affects Laravel 11+'s LocalFilesystemAdapter class, which was introduced in Laravel 11 and does not exist in Laravel 10. Laravel 10 uses a delegating architecture where FilesystemAdapter throws RuntimeException for local filesystem temporary URLs rather than implementing them."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13419e1f-2e6f-5faa-8f9e-00cf19891764",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0019cc2a-5eaa-582a-8069-0a38f89aa625",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:644b2c50-0d91-5813-ad9f-25652f01c6fc",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04f613ac-2f34-5e39-9463-6a135b7f2c7f",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7023c74-369b-5493-bc5b-72a8ba53bd4f",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccf7995d-9226-551a-85f9-d2e77b876eac",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d196bad-1b6f-50ee-8cbb-18e96bcb2ce0",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13080 affects version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e8982b2-40f7-52a7-810e-373253f0e9b1",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c33270e-a990-591d-9e37-05d1ce3d992c",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84fd0ac8-dfac-571d-825e-1cb6d3b7e0ae",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94e882d8-457f-5367-925a-a98d4ea609a6",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d3ece9a-0ef2-5723-a261-efff5191fd19",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f0dd658-faa4-5d62-aa6e-cf9ee65bf3f9",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f945215d-a553-591f-8420-936d726a7eb1",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8f860cf-486b-5065-8125-2dff5a422c63",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26961c0-48e3-56df-95a7-23d631332b03",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6366 affects version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:499df03f-b793-5061-bc47-a756914d8726",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a6a4fa7-e96f-5f15-83b2-dbc3802fd9af",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p3+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28d0590c-7da7-5915-b786-34b6877ad7b0",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p3+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d332d0fc-c02f-5440-b7a3-669abaf0ad30",
      "id": "CVE-2021-30130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-30130 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71379e31-cda4-5f39-9efc-49e549567bb8",
      "id": "CVE-2023-52892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-52892 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb08084-db6a-514d-a083-d1d26f5e5d6d",
      "id": "CVE-2024-27354",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27354 affects version 0.3.10-p2+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99216758-30f0-5302-b076-04cdea3d2fe2",
      "id": "CVE-2024-27355",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-27355 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40eb6a71-81c9-547e-8f71-672e9138fa63",
      "id": "CVE-2026-32935",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32935 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3582225-b040-5959-8b8c-743a9eef6b6a",
      "id": "CVE-2026-40194",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40194 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1927962b-0927-5ebf-aa6e-5bbdcdcd3d3c",
      "id": "CVE-2026-44167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44167 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e942a52-60e2-5e73-a19a-ce896ded2ad4",
      "id": "CVE-2026-55599",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55599 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5934c507-ed0f-5ca7-9ffe-a9557f7a7cc4",
      "id": "GHSA-m557-wrgg-6rp4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m557-wrgg-6rp4 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6946bfe4-4faf-567d-ae4b-7fe6d90b02e9",
      "id": "CVE-2016-10074",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-10074 does not affect version 6.0.2-p1+tuxcare of swiftmailer/swiftmailer. already_fixed \u2014 The target repository (swiftmailer v6.0.2) is NOT vulnerable to CVE-2016-10074. The vulnerable Swift_Transport_MailTransport class was completely removed from the codebase in version 6.0.0, prior to the current version. The security fix was first applied in version 5.4.5 (December 2016), the mail transport was deprecated, and then the entire class was removed in version 6.0.0 (May 2017). The cu..."
      },
      "affects": [
        {
          "ref": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395b4376-3699-5e2e-b492-e2a784cd11c8",
      "id": "CVE-2022-31042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p1+tuxcare of swiftmailer/swiftmailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c206d42-717c-5d5d-8369-3068080ca1b7",
      "id": "CVE-2024-28859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28859 is fixed in version 6.0.2-p1+tuxcare of swiftmailer/swiftmailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3c17a08-2970-598b-a662-2c22b6b5b450",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 4.8.10-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@4.8.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d9d6c0f-3acf-5db5-8f7d-4d9eafa5599b",
      "id": "CVE-2021-3007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3007 is fixed in version 2.5.6-p1+tuxcare of zendframework/zend-http."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:361b61c6-9505-5722-a6b7-13692f2b0b7c",
      "id": "GHSA-cg8w-5jrc-675g",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-cg8w-5jrc-675g affects version 2.5.6-p1+tuxcare of zendframework/zend-http."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e12f4df3-e1ba-5178-8e20-433e798102f5",
      "id": "GHSA-f6p5-76fp-m248",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-f6p5-76fp-m248 does not affect version 2.5.6-p1+tuxcare of zendframework/zend-http. already_fixed \u2014 The target repository has already been patched. The vulnerability (GHSA-f6p5-76fp-m248 / ZF2018-01) was fixed in commit 80b11a4c9a711ec50bca8892af91f809a2d1b958 ('Backport GHSA-cg8w-5jrc-675g to 2.5.6') dated 2026-06-24, which removed the code that unconditionally reads X-Rewrite-Url and X-Original-Url headers. The fix is identical to the upstream patch."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7586ffe-4ea5-5320-b784-ae71e58d8bf3",
      "id": "CVE-2021-30130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-30130 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241b4331-58b5-5c23-974b-3e56cc119d02",
      "id": "CVE-2023-52892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-52892 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e3b2987-0f74-5934-8646-9517443f1649",
      "id": "CVE-2024-27354",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27354 affects version 0.3.10-p1+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64756d3c-82e3-5dd7-a96a-ac59de94ba9c",
      "id": "CVE-2024-27355",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-27355 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30e80612-cb62-52be-897d-43f3dc7cfb8a",
      "id": "CVE-2026-32935",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32935 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbf07420-bcd5-525f-b3f3-0619d4a6abf1",
      "id": "CVE-2026-40194",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40194 affects version 0.3.10-p1+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93eb0c8a-dac2-500e-9c20-054647d2d496",
      "id": "CVE-2026-44167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44167 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bce2673-4159-59b2-9296-f2291593caa0",
      "id": "CVE-2026-55599",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55599 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba150099-1499-5cc1-80f9-0078ec83f7bc",
      "id": "GHSA-m557-wrgg-6rp4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-m557-wrgg-6rp4 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90790551-3eaa-5e04-87fd-d0b43d2400c5",
      "id": "CVE-2022-29248",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29248 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9f6d12-ff9e-5789-bc68-3ebdd778b61b",
      "id": "CVE-2022-31042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31042 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:310c9755-588a-554d-95a5-2441bc9c806d",
      "id": "CVE-2022-31043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31043 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ad416c8-910d-52bd-8959-b6b3b8bfbd47",
      "id": "CVE-2022-31090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31090 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf0661c4-972d-5a4f-9b8e-f60c4f6d05c9",
      "id": "CVE-2022-31091",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-31091 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2dd24fb-a359-53d8-9e2c-50e135d6c007",
      "id": "CVE-2026-55568",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55568 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd6dcd9-23e4-513e-9b3d-b53c3932ed52",
      "id": "CVE-2026-55767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55767 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:058badb8-6ec9-5f70-b0fd-63fb12eedb54",
      "id": "CVE-2026-59883",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59883 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76f8b5e0-b2b3-5fe8-ad7d-497ba494b71a",
      "id": "GHSA-94pj-82f3-465w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94pj-82f3-465w affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11bd95ec-9625-5150-a9ef-b9cd0efa614d",
      "id": "GHSA-f283-ghqc-fg79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e954149-7d7d-5bbb-85e0-c5a11f153aec",
      "id": "GHSA-h95v-h523-3mw8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b934cbf-7802-5dbb-bfba-8a66a4131fe2",
      "id": "GHSA-wm3w-8rrp-j577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle."
      },
      "affects": [
        {
          "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfb41473-ed2d-5c6d-a9a1-a6bd0e09f755",
      "id": "CVE-2024-50345",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50345 is fixed in version 3.4.47-p3+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac6c04c0-96f1-514c-b987-93d8a556b23c",
      "id": "CVE-2025-64500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64500 is fixed in version 3.4.47-p3+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9205a868-fe93-5dbc-b7a6-372d15aafe72",
      "id": "CVE-2026-6409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6409 is fixed in version 3.24.4-p1+tuxcare of google/protobuf."
      },
      "affects": [
        {
          "ref": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f76c2d-689a-5885-b5eb-6a5ea83e2ee5",
      "id": "GHSA-qjfj-3mm5-vrjg",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qjfj-3mm5-vrjg is a false positive for google/protobuf 3.24.4-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3814a663-da8f-5798-a1b8-2636ee0e33f0",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46870f5f-ea1b-5470-bf36-90a16de92621",
      "id": "CVE-2019-9081",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2019-9081 is a false positive for laravel/framework 5.8.38-p3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d87a47c-a734-54b1-93ad-b653fb5d7bef",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5450a7a0-9161-559f-9256-409cb5f18ef0",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.8.38-p3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3331f78-93eb-5e7b-bf2c-6c2db2770fa6",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33cabb4c-50a0-59ba-b481-e44e1f6d1a56",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52301 affects version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a3f7f4d-e6eb-5f3b-a4f6-4bcd08411c72",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80379fa1-6e8f-5238-b7e6-62d26ac94df6",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e56d6fd-3b05-5782-a934-9fa079e8ccb1",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39358311-31f5-530a-ae1f-37ab552a9f44",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b80e3dff-664d-54b7-aec3-1ab943bf03e4",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98480700-8f44-561d-aee7-abbdff783d5a",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:219ab51c-b6f5-58e7-bf91-d301a6b3a65b",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479cf6dd-c4f9-51ab-983a-9dca2d103458",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 9.52.21-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3462a472-1979-5c3e-be96-100b52755eed",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 9.52.21-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad53f275-9e2d-55c2-b3c5-e17b521684bc",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:442e3865-b873-52a9-83f6-582e3e6dcafa",
      "id": "GHSA-GCFG-HMWX-WQ5H",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-GCFG-HMWX-WQ5H is fixed in version 0.3.2-p1+tuxcare of nategood/httpful."
      },
      "affects": [
        {
          "ref": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b09c38e-4906-5fc8-9353-3dd0d485dd00",
      "id": "GHSA-gcfg-hmwx-wq5h",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-gcfg-hmwx-wq5h does not affect version 0.3.2-p1+tuxcare of nategood/httpful. already_fixed \u2014 The target repository (nategood/httpful v0.3.2-p1+tuxcare) already contains the security fix for GHSA-gcfg-hmwx-wq5h. The vulnerability was that SSL/TLS certificate validation was disabled by default (strict_ssl = false), allowing man-in-the-middle attacks. The fix changes the default to strict_ssl = true, enabling certificate validation. TuxCare backported this fix in commit 588532c on 2026-05..."
      },
      "affects": [
        {
          "ref": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfbcf857-eb98-565f-9feb-94419f107876",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 8.83.29-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6545aef2-9c3f-5430-9b97-601dc0390caf",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5293dfc6-815d-535e-8ed8-d19c72a452b2",
      "id": "CVE-2024-36610",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-36610 is a false positive for laravel/framework 8.83.29-p2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:777f5071-ee0e-5856-8aab-aadf018435d7",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee3bd374-65a5-5a22-9ec3-35e6d1f44657",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.83.29-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb323757-9d06-5807-8518-0b811a54df66",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf81ac5-ede6-577a-9107-625d1bd67d68",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 6.20.45-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10839f3a-25d0-5c2c-9fd3-29f721360209",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 6.20.45-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ccd262c-5757-5802-b4e4-8c6fcc84a069",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-27515 does not affect version 6.20.45-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944d8599-f5f8-56a1-9106-112488a69a33",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 6.20.45-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:678099c1-54a6-54e2-8681-eb5b8757f0a9",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 6.20.45-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f40b4676-3cdd-5fa5-a456-27024d28c2a9",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96f0867e-2cdb-58bf-a8c2-53825025d58d",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 7.30.7-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2702318-71a3-527c-bd72-095775695d73",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 7.30.7-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd50a224-a250-52bc-b8de-053f842c9eb0",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 7.30.7-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8681544-8782-50db-ad04-2e5cac35378c",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:197d54b0-3cd2-5d37-9cac-1549d4dbfa9b",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 11.51.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5de0811-24fe-5bf3-b470-c15492483b0e",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 11.51.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:113c98bb-df49-5f1a-923d-4e41e97e0232",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 11.51.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dce8101-dd75-532a-91fe-32c108770c73",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 10.50.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1105035c-9bde-59ca-900d-441a41d7f124",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 10.50.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e1c18c4-76f5-58e8-9f04-eb5f380a70c2",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.50.2-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f03b17e-af28-552b-a984-16939b1f4b05",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b084d4dd-c298-55d9-9008-da6c8cb255c8",
      "id": "CVE-2019-9081",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2019-9081 is a false positive for laravel/framework 5.8.38-p2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcfb6931-fa8f-5470-bb07-b7f2ccfe2148",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2c336f2-89ce-5eda-93e7-2c53db38f999",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.8.38-p2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e270ebc-b30a-5640-8554-025110520a04",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de55bad4-7bbe-57f1-9203-23b715161407",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52301 affects version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a56394ed-aadb-5eb7-a9dc-09adff982f94",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a818f21-1246-5701-b76d-767ab0c12774",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62ef5e0a-de8a-54bb-9567-0fad92d8847f",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7f319ba-07c8-5383-999e-b1bfaa38dcef",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:756f6fd5-6970-5fe9-9e26-e2b535b4102c",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e8aa0c-d841-5c06-a8cc-4df0f2134111",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f736d204-c8d1-5db7-a63c-7c6307fd3288",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aae3a96c-4244-55b1-bd47-284e225639c1",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95c1b94e-fcd5-5190-b566-104f3ab1ac59",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e58c006-415f-534b-8f2c-42b5c813dc0d",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad56877-f87a-5ced-9ffd-c760294b5a21",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b03b9935-3f7e-5838-952c-b5f26bd35a81",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c80846-26bd-5aec-9ec2-d6642fb09a72",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13080 affects version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7908016f-1e29-506d-8296-2c0375c97dc9",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8bfa6c6-cda6-59ad-b9dc-6767977879b2",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be7c56cc-491d-59dc-9f76-0cd2135d8d16",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb74059-8447-5d53-8472-17aedfec4f70",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b35cce-34b2-5295-a694-2ede3209f8f3",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cf07b40-8b87-57b8-bffb-78be6ed30629",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b311f96-86c6-5ae0-ba96-ccaf6f59671f",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17e1b5d-70ca-5501-b433-a1b2f77ecc84",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9840d7a6-a1ba-5834-88ef-2720e71e38b4",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6366 affects version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e1b0aff-80f5-53ed-b48d-013e993d0c3f",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-9082 affects version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b406811-6f3e-5b73-88b4-73a72b8ffcdf",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p2+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c08b0781-95d5-5e51-a075-1b288577ea7a",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p2+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fe472b6-cff5-5712-928a-517393a2ff26",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10659 is fixed in version 12.58.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fde97e2-71c9-5eb3-b3f7-91a8063edf25",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 12.58.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf838b6a-87c7-5574-b827-27698dc7f39b",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 12.58.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a98b09a8-36c8-5c1c-b04a-01fe4720c077",
      "id": "CVE-2014-2681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-2681 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a284ae-9dea-5480-a59d-33517b6cd9ce",
      "id": "CVE-2014-2682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-2682 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62df0e13-0e63-5fde-b18f-043a7f749f38",
      "id": "CVE-2014-2683",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-2683 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:006c6482-3d54-5484-aa23-6f86d37c8bbd",
      "id": "CVE-2015-3154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-3154 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b64a6e3-48ef-5481-a53e-a4f476796604",
      "id": "CVE-2015-5161",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-5161 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bdb4530-f0ee-5de5-98c1-497b935c9305",
      "id": "CVE-2015-5723",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-5723 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0976e051-1a5a-5aab-bc88-d9f5ba631acd",
      "id": "CVE-2015-7695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-7695 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d44159-a75f-5b11-a7f0-7370b104a426",
      "id": "CVE-2016-4861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-4861 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c61f8fd-bcc0-5af2-a0ba-1cd5914a1f4c",
      "id": "CVE-2016-6233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-6233 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:900c74e2-7dfb-560f-9491-171fdc400ef3",
      "id": "GHSA-6fqw-j3vm-7f66",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a73e11b-685a-56aa-899d-75bdaeb19420",
      "id": "GHSA-848f-mph5-9pm9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8719aa8d-8da0-5031-90c3-e4f57441613f",
      "id": "GHSA-8xhv-gqm4-3w99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:352b1a77-12c3-5fb6-9ce2-0c29389d6a19",
      "id": "GHSA-gff2-p6vm-3p8g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gff2-p6vm-3p8g is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73b6ddd8-3341-5cc9-9e7a-9f03839eddc4",
      "id": "GHSA-v42g-7q2x-cw32",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b877d03-5c3f-53bc-b207-e15ac4e744a0",
      "id": "CVE-2021-32708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32708 is fixed in version 1.0.70-p1+tuxcare of league/flysystem."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/flysystem@1.0.70-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b1f480-1469-5d06-89d9-f8f0bc7b4687",
      "id": "CVE-2021-32708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32708 is fixed in version 1.1.10-p1+tuxcare of league/flysystem."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/flysystem@1.1.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fff9d28d-1c73-54c6-8a22-9c138e81a7ee",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-15133 does not affect version 5.5.50-p2+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1148468-ee69-59e9-b0cb-b7e8ad4b485b",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3662aed2-63ec-56dd-a110-a34bc570d3de",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ec4b3d-481c-506b-a523-00bc8bacd45c",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4c84b6-91c6-554c-8d6b-461903abd29d",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49b8133d-69ee-5d1a-8338-314764ff6276",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43617 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0484638b-8609-548c-ba51-11f38a312727",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb59f51-5763-5dce-afb1-d4a1a81589d6",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.5.50-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d6cf680-38b8-5609-9e55-4b0bbae63c5c",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41094eb5-f819-5246-81d3-3bb2701f0252",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc38e74-2292-5c5b-8627-2bf0896f12a2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46d14f34-ec0c-55cd-a074-3a3cc4ab20a7",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.5.50-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:827367f1-aad1-5208-ab96-1112a868a901",
      "id": "GHSA-6jvx-8ch9-j2jr",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6jvx-8ch9-j2jr does not affect version 5.5.50-p2+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956ae932-27c9-513c-ad3c-9eb0ae5ba3e3",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.5.50-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6331cc56-fe02-5326-b88e-ecdf2680bf37",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a16998d-81ec-500d-8424-5995fc35436e",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.5.50-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c23fa3f2-6939-5e6a-b076-3ff23cc155a8",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e29326ee-7973-54b1-a3cc-ee4c53752a4e",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3b88fe1-34ed-51cb-b4ea-39153cc3a498",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da08d219-1476-5ee6-be9d-3ad76177b4f2",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:092912d5-5659-5c57-bfc7-4ec19725ac31",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbce2a9-9c52-5f1f-adb6-290a32ad07ac",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7435ed6-f35c-5bc6-a855-eb264030b520",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ea4711-c043-5a26-9d86-af84e863968c",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd73a0a-108e-55c8-863b-54c73c11f36e",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9479b9a0-93ea-5cac-b6e6-ec8814dbbda4",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p4+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7777b136-f86f-563e-87dd-98f4d6f3d028",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4b074d-630e-5be5-9db7-056e8b9303ad",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28630a9c-e179-5813-8a77-e54e9dc39a15",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84af90a0-8031-55da-be85-5838b93f3cf5",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ba8f739-3497-5439-89e9-d0009b215c28",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d425296d-873a-55ef-aa53-0d5332cd4c5d",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be46b7bc-e6d8-51d0-ab08-2186d2b78712",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9588ff3e-1830-54f6-910c-f6e1f3d53816",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e688d9c-45f4-5f6b-8d3b-10f3d1527c52",
      "id": "CVE-2024-21544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21544 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3393de45-8127-5073-8ff7-58bab7c6e718",
      "id": "CVE-2024-21547",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21547 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9af10e-d9c8-5745-ad8b-8095fe59a9b4",
      "id": "CVE-2024-21549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21549 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea0b742c-0979-529a-a906-de6c4053c39a",
      "id": "CVE-2025-1022",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1022 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cbcef9b-43fa-51bb-9e41-936e24365b92",
      "id": "CVE-2025-1026",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1026 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d578163-28c0-5ca8-b5d2-99c8ccce13be",
      "id": "CVE-2025-3192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3192 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52b123ea-0d85-5402-95b6-2ca6b7aec780",
      "id": "GHSA-vjrg-wpm8-rhrw",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-vjrg-wpm8-rhrw is fixed in version 2.8.3-p1+tuxcare of doctrine/orm."
      },
      "affects": [
        {
          "ref": "pkg:composer/doctrine/orm@2.8.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04aee992-6165-5f69-b6b1-a1109ec43889",
      "id": "CVE-2026-30838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-30838 is fixed in version 2.7.1-p1+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a11c085-26b6-5414-9a5d-4359da1ddae5",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33347 is fixed in version 2.7.1-p1+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de6303ca-c310-5369-b5d9-4c590afd46ff",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e086002c-0b9b-534d-a94c-2cdd03b304b3",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f839658-3231-5e02-aaa5-15783b5c0f84",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69359fa6-e1ab-5eb3-abc9-b4d947bbadc1",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f04e9d1-6b1b-5754-a931-6559827ee366",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60053f90-327e-5a15-ba62-99beca171135",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2257b0a4-f0ee-5084-be35-1014b68e0e54",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd00eaee-fd44-53b7-aeb5-83d41bd86dc0",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05958fc-b09b-5b9c-a02e-1af6c3ffd59a",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07dad952-78ff-5b7b-a125-d18ba73da594",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a57b4521-9f8b-5610-9b01-e770218c6c20",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5977227e-1220-53b4-86ef-99c6f0ccdd90",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fcb9160-da7b-5fdc-ad51-1747752dd9d2",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f55e8fce-bc18-5cd6-9fb5-e17e431dd831",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:878bc2e7-b1a1-5752-8bc7-0f3ba62d1817",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be2eaa5f-3165-5c03-8c5e-93ccae1f8710",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0f97405-9dc6-5b75-b4b6-fe034449a58d",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c84bd6-cb8c-52b5-890b-12564d40af27",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8cdf9f-a871-5254-b449-dfbe883e8f59",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:027386bd-22ff-5296-89a6-c00acb9194e8",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c9db5ff-c67e-5196-a50e-319e9018f16f",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4341aca6-53b9-5563-8979-e56e2633b8c4",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9d8d1db-a83a-5ba5-80e7-ce329b17206f",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91aadcca-8966-5882-b829-ef8e7c1862a0",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0543395-8ddc-5c57-8418-786584c9fa0d",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96f17d1-d939-5faa-b432-0d0a8cb39eb2",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a85bd8a2-707a-586c-97a5-2f4aa2f5302d",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8463a05-f4d1-5c0a-8e6d-dc4371c10d41",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:327735cd-dac3-5153-b86c-5c529f92c498",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7c39e2c-b68c-55e5-b2c7-0168f87bca54",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e06070f6-8b97-594a-a940-ff2774329e97",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51f56fb-db15-532c-90ca-afcc6843671d",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d90ebfef-0073-5b92-baf9-ed8023b78dc8",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25496 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:991b4a57-da61-58cb-bd3e-1a1727a984b8",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e773fc1f-b365-5e1b-973f-52aa1b23e114",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a25ccef0-be3e-5460-a9dc-b9a65930fc9d",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b51cfd0-7a6c-5034-b1da-e32626c4d6e9",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b96e010-0d2c-5fa9-af75-7285cf30e132",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a23e612a-dc4f-52d5-9d3b-2ade5d1ad87c",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5d4f0d-2fd7-53c8-9e26-37f24742f8a2",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f10d9c38-a4bd-5663-9e95-87809ac5f17d",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:725ba595-3788-551d-964c-f336bf147c1a",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d52c6b-3292-5ed0-aba8-88c2dcdf4a14",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ad83ea-bd99-5eca-86b5-2cbf35d456dc",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13747a55-958b-59de-9144-3b8785feeac5",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9964663-c835-5ed0-96ce-413b6ab3535b",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df469432-db6b-568f-b331-d858a41e5303",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69a9116a-fa1e-54b8-b06b-3b1724cbce6d",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a46a9fb-dcf4-5ecf-bb40-5f7ad880ab40",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b1bd900-426c-570c-964c-65fb22132bba",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:809905eb-8163-573a-8704-7e893f101a6c",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca9ee775-621b-57ce-b28a-d8151602144e",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ffedeb9-9946-587f-bb7f-2ec0dbcbb4f9",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2e94cf-f3b5-514e-b1e2-80bf64c304ea",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eba150d7-d5c4-5603-9b14-c7b689246383",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2969e904-5ef3-57f3-a6f7-e149bb2a1c33",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97abd7b4-f7ca-5996-a905-a1f43dcc4544",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82c881d5-0aea-58cb-b34d-d04855f9fe8b",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55790 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6ef0f9-2f52-54ee-bdc4-6279e676e078",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b41a09b-aee2-55bd-926c-0ca91c2daa5d",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7dce8c5-c663-53a6-b4b6-b0fd33f712f5",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d597d48-d53e-5ed5-bbc5-2420752ac32c",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a145954f-fd23-5967-871a-1cc7975c2202",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1913776a-5557-5912-bbc8-8300b150e44d",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d0f58f0-7c12-59e9-b9da-d3ddfb86f3a0",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7661048e-f355-5678-bbc2-ad5fd265fa45",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:760e127c-40da-5911-a132-09e57de848df",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p3+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b2b09bf-54da-5eb0-99fe-87c0c9e97965",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 8.4.3-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@8.4.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cbdae13-0855-5b79-8b00-68d32ee1f522",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 7.5.20-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@7.5.20-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98be72b8-a879-5dbf-889f-9ab9503975c8",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 9.5.28-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@9.5.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1529011f-6cba-59be-9146-e47119729ed7",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 6.5.14-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@6.5.14-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:406f2e4e-e61c-5e5b-a537-086c18bfbd2e",
      "id": "CVE-2025-46734",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46734 is fixed in version 1.6.7-p3+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1656695f-1803-5ee0-bc62-a37ad60c9e6f",
      "id": "CVE-2026-30838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-30838 is fixed in version 1.6.7-p3+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38b0adf3-ab41-59a1-a5e7-c7aa009864a3",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p3+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:589cf5d1-db95-5f2e-8ca4-95da14862a64",
      "id": "GHSA-c2pc-g5qf-rfrf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p3+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea3aee09-5df7-5a61-b92f-a532f430f453",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 10.4.2-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@10.4.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b2dbc53-5419-51c8-8b6f-6bc209670b77",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34574983-7238-5254-9ad0-a8382e0b2cee",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:217301eb-8497-5c65-9128-f5b0f72b3503",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a6d2991-5bea-5f60-9fda-0f952633075f",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee3aedd-f186-5b64-8d17-29832aea20f0",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72267330-5833-5d08-a183-321792f8c0fe",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p3+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21888766-9627-5543-808e-70e6887e012f",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ee64c0-d889-55ae-828b-2dcb5ea69ad3",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c93336b9-45b3-5d88-8a13-5cb8b309e7cb",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3ece3ae-ac0f-56f0-8f1d-6d2ebff857e7",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f10cafc-d135-5036-ae99-5c0a32a6b27a",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f04f005-a782-5cfd-831c-211b23c7f402",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6494e6b-e3b9-54a8-846e-dbcaced77bfa",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47664ad0-a087-54a4-8295-6cb4af7793e2",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.2-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9b5f878-9ca6-5815-80a0-b7b539b1d988",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9760f461-d242-5fa2-97c5-b9e92bc7af62",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:215f5c21-0b7d-54e1-8272-ed32ab0e68fa",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55ad2c53-997f-5aab-be7a-2ad50cb290b0",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33347 is a false positive for laravel/framework 8.12.2-p1+tuxcare. false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7cb424d-c26a-5995-b478-0475aa2a93ef",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fad2d71-1330-52db-abc7-a7e50d0d34db",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b47fc96d-e92e-5fce-a625-aa6ff907acf1",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.2-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8781db4f-54c2-5c78-886f-4087fcba50b7",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c614fd75-09c6-5969-bc84-fae76e495e65",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:368ea6ab-fba0-5003-b96d-4e3797c0fcd4",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.2-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:855293c8-c2f3-5522-b5af-aba21d6fa623",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01bdd4d4-e17c-5433-964c-364df643670d",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:101713de-49c8-51ed-b968-a3d19ef8d83a",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4f6998-4082-5416-a809-d36083390885",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01295ec3-aeca-5cdb-8438-7ff779c841d3",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e413b470-748c-520a-a581-bbe7f5e1b315",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p1+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c87f6274-d929-591f-931c-919df1d277f2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb611376-0987-5c34-a6ac-fa8a72d054ce",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57a9d1bd-6b65-5b7c-9eb3-736b30ce6794",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8135816e-0a06-58cb-bba3-cb28d905103b",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99cd421f-b08a-5c98-b2bb-4d6ce2177385",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69860cc0-b076-5b66-a378-490fb6187f8a",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c34c21a0-5b30-528e-b173-3fe811a3ac1d",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a523865-9797-5903-83e5-64168707cff5",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.3-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23841fd2-e1be-5a11-a8d6-8d5f1596aaac",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:485f27cb-5491-5efc-97f4-9e9eaa1d25d7",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78f4ce64-f1ba-5ceb-b1f0-33afcce14d52",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdeb541b-11d9-542d-902c-89d8091f91a2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6afcb4be-22a1-553d-913d-49324a844b97",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:733b75e3-ed2b-57ee-8d83-f668a7a30b2a",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.3-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9f5e01d-d32b-5d25-a88e-c223e7984304",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ad96f4a-7d72-56f4-922a-41e3ac2e33cb",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab91aaa-666b-5cf1-a68a-0040a951c723",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.3-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c2e1d4-1a5d-5909-acf7-4aa6c45f1c2b",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05b78f0-6da4-529f-b881-0da82da1e41f",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94da944f-7c9c-52b2-9190-a7901b7fdf29",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c9bfb2-4a77-570f-a980-a669f015c136",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe34699-6439-50fe-ab8d-c98778da5784",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:374490c2-5f02-5dd7-9f71-b9bfbeb7a104",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dab53bff-13cf-51cd-97c1-6f87e5e16d67",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13080 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97917afb-afab-5281-adfa-1a69649042fc",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eafd0ae0-2f1c-5bb2-a20e-d33a5e18b867",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41068807-85c8-5b0c-932d-b15a61cfcb79",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e943d4-cdf6-53dc-89df-48109c50bc74",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c3664a8-e8d2-541b-b306-a0f1caf047de",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df53b01c-2fb1-55b8-9ff3-b8412c549740",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc149b38-9476-5436-8388-177dcd4ef0ac",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c660c9e1-114f-5289-b601-8744beaf3641",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6365 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4cd788-0781-50d0-81bc-b79cfcef28e8",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6366 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d2a783b-d197-5310-b3f5-6b7243ef48df",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-9082 affects version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91928f8-fee6-5dff-b7df-21837ffb344b",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p1+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3a0a78-37d9-5b5a-a46b-fb4f5e4a0ea1",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p1+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63628c74-7267-5e49-9364-36fd31187d58",
      "id": "CVE-2026-33182",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33182 is fixed in version 3.15.0-p1+tuxcare of saloonphp/saloon."
      },
      "affects": [
        {
          "ref": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b80ecc74-f1bd-5182-8590-b517d27ef92c",
      "id": "CVE-2026-33183",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33183 is fixed in version 3.15.0-p1+tuxcare of saloonphp/saloon."
      },
      "affects": [
        {
          "ref": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a02e5a9-8f26-5c76-ab98-46e135fe88ec",
      "id": "CVE-2026-33942",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33942 is fixed in version 3.15.0-p1+tuxcare of saloonphp/saloon."
      },
      "affects": [
        {
          "ref": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfa3782e-0a04-5986-9d3c-c15d36295a51",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dba668e-b9af-563c-8519-ec5b11eee057",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6bfa34d-1bb0-5114-9ec0-4e888e36388d",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58bdaac9-e3dc-5175-b83b-d83b31858b19",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e3eb3cc-a962-5b0e-9a23-48520a49276b",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0b9fe7b-af14-5ab7-acc6-7092299a63d8",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1ee3e6f-73ce-5d2c-a3fe-92b0a9d17aca",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:385024ad-b7c0-51d8-a1df-e7a00a05830c",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c3a14f4-b642-5790-abc7-89ee08220255",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb5c65e-0346-52e2-bc82-e4f98f471d6f",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae7e508-51bb-57be-b732-6d7148f9b8c7",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc0355e-744d-54f0-bb7f-699aae99b125",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b91c25-e9a7-584d-9b63-900307a0fe65",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c93cc3ee-0bd3-5c4f-9091-416ca1259b54",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45e5896b-fcf9-586f-8831-e035834c8130",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1041e1b3-caf5-577f-8b58-bb0b42ff10b1",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e1b57df-327a-5e36-9e96-98cf954de621",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a071f12-8580-529a-9b37-b0c411d6af60",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82eb1498-fd07-58cd-b6fe-b187376dba9c",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e88a5226-e416-501d-8519-21d19794b051",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77363320-04b1-5f26-bc04-a90147181c63",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08bb8486-2535-5c68-a7a7-4782871602d3",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a906b13-0213-5cfe-9845-c7a232e1a760",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0490bd7e-6c69-5542-944d-93dbde0f6dbb",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af7f3b83-b912-509e-97c0-065eaf127e65",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68437 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:878318b7-890e-5242-8868-b0cc70587ed0",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7991f4d7-ad8c-56e8-91cc-72de63146b1c",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aab6f3d-090e-5859-97b3-993bc47e1947",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a7fc55c-b979-5ecb-817d-12ab8a85da4a",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:126080d6-2e02-5804-8576-10bfb64c2a8c",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f737a2b9-cd82-5739-8bcc-43f845830d15",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2583bf4-6cf9-595d-94d5-73dcf423c662",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235c1ce6-18ea-5269-b808-4ad6e8809f3e",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25496 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6e2bfaa-1ce5-5d0b-9c51-8a632ed87dff",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5828803e-6a55-5599-a9e2-943f1b139f14",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9924c4c8-809f-533d-ad81-e47fcca5dfb1",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27127 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93ff2eb3-3120-582f-a4f3-e16258d64979",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:532a5e92-133b-51d6-87b0-638a3d6b5ecd",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e243384-5ae1-51ed-83a9-5150c3d9cb25",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d24bf00-3a87-5b45-affc-2f6d5eb729dc",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9709168a-adab-5b4c-944c-5d52c4a4302b",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e33a858-9122-577c-8202-84129694a2a3",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60e73852-62ba-5ca8-b59d-ea23a21f94b1",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:088c8bab-b761-52e2-b219-d8e42a05bd5d",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:923b5cf4-8c71-5a8e-aae6-cc3a4239beea",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d673b02-c515-5be6-8942-8bc2dfda85cb",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a11cecc-c1ec-5808-8269-b861aa2db37b",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ef0c49-1287-5903-84b7-eb561551c91e",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32267 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22cd1033-c3ef-5c35-ba92-3ccb6d9f01db",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0b611fc-9465-52e9-bfa8-0041d33d37b2",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2576706-753c-525a-9ff9-671a71cb0a4d",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a436c7cf-8f73-5d19-9e7e-9c1045316be1",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479ec2e8-7216-5e77-af68-ca47c4af21e4",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73b245e6-0deb-5dc8-8ba2-69450d0d319d",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48432d46-bdae-509b-9129-5dcf492bf50d",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28922a25-4787-5f10-b0ff-4e4c59e408a2",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b474d613-9c71-5d33-9dec-e22bef2d5b27",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:960f1a58-a833-5718-84be-ce0eefcac8a9",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55790 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b2ae6f-0471-587b-b02d-e4f9e26ed080",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea5f6c47-f168-50ba-9059-a8473b42a082",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14fa7e09-abcb-5b45-be9c-122f835f3468",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:179aa84f-2034-56c4-8cd8-8689706ed203",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9bc1669-3c35-5f51-bfb7-04ef8582627b",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b53a7a06-8d23-51a6-8f32-6f430988ff2f",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef76160-92f1-585c-ac38-a8d0190440dc",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e249dc6b-9e1b-5c7d-ac79-1a83190152ef",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa7d73a-cce6-5f41-af30-d43abecd7ab1",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p2+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f538e8-1344-57a5-a27c-1fc12bac3d96",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b675db5-bc65-5d10-b1b2-0526e0fedaac",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e36d45-2f8d-5b01-9d70-e7b6afdc41e7",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43808 affects version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d0e3dc-bc4e-5f81-83cd-6707c847b043",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52301 affects version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715f4de5-6485-5722-8768-96bb2c7d97ee",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8457435d-299b-5c29-b24f-56f0e765cdcb",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p1+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:206f76f5-af14-5f6c-bd1b-720db09ba155",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c8da68-86e5-53b8-aeaa-92a4f34cf589",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c49eca-22e1-55c3-8035-a2646ee02d02",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a4c9fd3-e72a-5802-9ac1-e97832fc74d9",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ac5ade-ff06-50e9-9f67-e6352dd67fce",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h affects version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfb34aaf-a43b-5617-b7e2-077bd22ef4de",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d0f498d-88ba-53d6-8b20-9ff964c6955e",
      "id": "CVE-2024-50345",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50345 is fixed in version 4.4.49-p2+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9711dcd0-1ea7-59b8-a9cd-b3f5a1c5c607",
      "id": "CVE-2025-64500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64500 is fixed in version 4.4.49-p2+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f973dfa-3b2d-5fda-a7e6-fc60094b2851",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63270696-d5cf-51a3-804c-9d722db430e5",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5147836-5d05-52b9-87bb-0b4fcdabc6df",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c3554e-9d5d-506f-b2e1-ed0bcaab7b3d",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4800590b-7158-56bb-a1bf-dc3b81168604",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b917950-1694-53dc-8b68-98c41381f7e7",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:079fff9e-8932-54c3-8d9f-a5b12886a4f6",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec68f49-7ddf-5777-a73f-4997dad2d77b",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:691dfc6e-7808-54f2-93d8-a7a9d2b3b930",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a9136d3-bddd-51bb-9965-a25170c7f079",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6647a7f9-af5c-5226-99cc-d56e77a21d2a",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56510053-3f31-5470-9f16-7516fdbceedf",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b937cd64-b7c6-5c6b-bace-f9093a88e111",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05856c2f-4edd-5935-aadf-894ce02998dd",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ba948d-3627-5308-b6c6-c294fdda372e",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34840885-1be7-532f-83c5-859c43e8fce9",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4cb6bc-906d-55bf-a13f-d9a708ee4365",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df93b646-6dc0-5db3-8233-3175d3d25aa6",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b41a94-32d6-586e-b5a5-75c6179f4644",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:842128f8-3cdb-5094-bd7b-deb1eff39c3e",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b50777-c826-571f-9b18-b147a5e0b1a4",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9abb02b2-d714-5820-a89b-1ab85b614869",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745f7295-1b49-5f84-903b-931d7c87c0c6",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a31bf3b-8954-5683-b814-018cd861b9cb",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56f4ca8b-bb7f-5a5d-88e0-dbdd944484b9",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68437 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:694e196d-47db-5a66-acd6-f4a75501ea5b",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c64f69-e9b6-5e71-8047-85e06359962f",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22f56c1d-15b6-53c1-93a5-3002a5f857ab",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:764c1861-7e0a-5d0e-9812-617123055999",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67297ec6-dded-5270-a69b-e282039ed06e",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64f224b0-4dd2-5448-8cd6-a0114cf519ce",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ea07aec-60fc-5b25-b283-1c4aaac52c9b",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb0b61b-09a8-5be9-81a7-ac46b73c7286",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25496 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc8b980-5cff-52ab-a5e3-d6468054ecdb",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060274fc-6a07-54f3-b1fe-fdebc6052d7d",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d2ae5c5-7fc1-569b-9ea9-79b23d8f568a",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27127 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:379e00e5-7fce-53f5-a161-040c2678deb4",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63a33bbd-72e5-5efd-91f5-e431832a44b2",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:843cf02c-8fee-52d4-905d-c7ec1f823943",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28783 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68433060-fa14-5964-bf5b-bbb345e2423a",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29069 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a30f245-7b3b-5e10-8dda-92eacd273c1b",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3165fa6-5f45-581e-a8f6-619ce0dd16d4",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a10e1106-25df-5ede-a8d3-c4b89c8be732",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abbf8b38-de6b-5ea0-9812-434e4a951f8b",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:130cb96d-aee9-5680-9ab3-83656330d930",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb4f5a4-54f9-564b-831b-ffb238ad5c70",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bb095de-1194-56d0-ad17-0b91a6106492",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b1ced06-52d7-57bf-9e83-065c82cffbdd",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32267 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad0aa36-dc88-5d10-9948-0928e2af42c9",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b27d88-77c2-56cd-a13d-c918fb3853ac",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78720238-0657-5349-8a16-9a7860cfaaa2",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1098704-c878-5126-99c9-d3ef6f6659b2",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78e148b8-43bb-53d2-9334-492513f07373",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2b946f0-744a-5381-8607-7432758f11c6",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b7ce7e2-0162-5f88-9561-fdd88ca4e074",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e305073-c3b9-59d4-936a-f9db8e52f664",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b43b225-5607-5ad4-9bac-759800b4482f",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad3e647-cf0a-5978-8b32-aecf8d981b30",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55790 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a47e1f8c-e581-5611-a8fe-c96af2216906",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e840b06b-550c-5e3c-86c1-d5d5389f7a08",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:668e3bea-92f7-510a-bb96-8c6d52ecaa13",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0459c57-c1c3-5c19-9bdd-4d693a9040c8",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:464b0a4a-3c06-52d8-9ae6-bf721a7bb58b",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86205780-7bfc-577b-9ac0-333999dfb2f5",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8f6add-9f9c-53dd-8d1e-8f9361b0b322",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0837d48-81be-511f-9bcf-ba518d55c8cc",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efa45c0a-ba9b-5a55-a70b-298494f98190",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p1+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2213917-fdde-5c2e-b2e7-4cceb81ff4c0",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c970a6ff-4938-595c-afb0-645ff3bb1cd5",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d009dcd-ba07-5833-a95a-5c3dda10aaf2",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73aea92c-1e42-5544-8989-2b3c49d4f310",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5339b7-28de-550f-b5a7-248baa58aab4",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56729dbd-9f12-5536-8bf2-8c4b67373f1c",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:033bcdc4-669e-56b2-bdb8-e06027250a70",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4c2d99-0843-570c-a174-b38f02270647",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a7e8cc6-a5c4-57b8-b9a0-96c1b86f1af7",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb99a99b-8b3c-5f53-9bc5-115fa63dc215",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:714b509b-97d7-5394-bb71-03051fc105dd",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7988e5-f6eb-51ce-8589-572a96592ee7",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bce8974-40ab-5cb7-a76c-51522c4ed958",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2ece653-a4b1-529f-965d-cbdb493cba42",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b18da7-ed81-5551-b70a-252cd3d58008",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b76d225-6b61-5384-a239-eeb27fbe96e2",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfc4bf39-bc8a-5a23-a03e-410158a60d3e",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4db55a9-abcb-5f96-88fc-d98ed9e38b4c",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b90049-5916-58c7-9538-6582a4d98f86",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9421d4f6-f281-56d3-8dd0-57068ee00545",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ff0f16-195d-5f34-a23b-77fe8c905889",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:621085d5-09f4-5f1d-9059-9bf04daf9634",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b51517d-54c7-5534-84b8-2a71abac8b31",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff3b749-75f2-5beb-9caf-239f364c9c2c",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0416a2a-5089-5c4b-a2ec-0592e8745e93",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b96f88-0d63-5d5c-a2ad-f7cc173ec5bd",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d594765-c942-5490-960d-0e4f3e919b9b",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d518f50c-f141-5447-8b1e-4fa79adc049d",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ae0c4ef-4f7a-5105-89eb-efa489b3248b",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf172815-efb7-5ae9-bb1d-c24192491550",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f041277-896d-518c-b889-7456d52f83b7",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6009a738-8690-57af-a987-8fe3c4f4ce67",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c8d9d2-eeaa-5437-a3ed-eb23fc2253c8",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c76895-8ca1-56ef-99bd-cea4bc5bb5e5",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f27ed7b9-d118-52e1-8c40-35912016c689",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:591691cb-ce8d-5460-a15c-ee364998aced",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0e436cc-ddc7-5133-b24e-dba4be22d8cf",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9d34c15-13be-54d5-8005-282cad63e96c",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad5b853-4ffc-5350-9cec-7d848d9e923b",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c705c461-a7a4-53de-8e69-c5c4c679c12f",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf49e314-fea0-51d3-a576-2b55ff96c8e8",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
      },
      "affects": [
        {
          "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b6c539-de61-5e22-ab1c-ccb35f0f310f",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5de9ec2f-f48d-5eb9-b7bb-1dd3b2bf49b8",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcacb735-0ab6-5f60-b5c0-8ce9f1022c7f",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b639d6ae-10e0-52a4-8072-9e236bf0c1ec",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89709b56-b509-5a8d-a41b-8f14aa6156ee",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a86d8a3-cfd5-52ba-a374-789979940eba",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9014e98d-c590-56f9-82da-b9f1893cc6fa",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e212a6a7-0b3b-53f4-92f6-e78ff1c5beb4",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee80b4ff-e40e-57f1-92eb-b5fe255d60d0",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30444334-1bf4-5489-8ed6-065367d74920",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p3+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3790af7f-71d3-5501-ae78-eb09b7935663",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42c30fcc-743b-5142-a68a-c09f3c2554ae",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:840ca0a6-e9ef-5d95-aa57-fe5a6de57f84",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1355d6e4-2627-5cfe-bec7-bf8b814b24d7",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb27cea1-9a14-585c-abfc-f1912762d13b",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cdddb41-371a-52aa-87ff-37c3036e12b3",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ff1f08-f9fa-59cb-aa69-115f985cde2a",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5919e9de-9bd4-5633-a059-12068e622f51",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p3+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:865a1c32-a572-51e4-8bec-fd10f5f0d352",
      "id": "CVE-2023-50251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50251 is fixed in version 0.3.4-p1+tuxcare of phenx/php-svg-lib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd8f5264-b6cf-5d0f-8ede-f5a7602b501a",
      "id": "CVE-2024-25117",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-25117 is fixed in version 0.3.4-p1+tuxcare of phenx/php-svg-lib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aa66d53-06f1-57c1-bc73-99860a7a17dc",
      "id": "GHSA-97m3-52wr-xvv2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-97m3-52wr-xvv2 is fixed in version 0.3.4-p1+tuxcare of phenx/php-svg-lib."
      },
      "affects": [
        {
          "ref": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b9522ff-4ec1-5818-af1a-6053e0c590ec",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 11.4.4-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@11.4.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:547962b6-6cea-5b7f-bb2b-0602a20dde2a",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae62f0e4-f63e-58ff-9f09-c18c803067d1",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a757e40-a69b-5479-97e4-6a21530486b8",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4549f816-4e7b-5041-93cf-cafe3af05ab6",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f963e17c-9eab-5a14-9792-8c0370192ebe",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.6.40-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d43004-a15f-564a-bb0a-d2f25ce04e6c",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c383eb-1539-5b2e-b8df-9bea6f810406",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.6.40-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98f369c8-ebc8-55ba-86c9-7b54f3381d94",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1173bad-2073-5100-b767-0e95c8672ed0",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9682fe-1ccb-5fe3-9421-92a7c09a62f2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27d51d52-6882-5439-b52e-f73307410faf",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.6.40-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40-p1+tuxcare uses SwiftMailer 6.3.0, not the Symfony Mailer targeted by GHSA-5vg9-5847-vvmq. SwiftMailer's Egulias EmailValidator provides CRLF validation that prevents the vulnerability pattern from manifesting."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1164379e-150f-5f92-b768-95459cb2b5f1",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.6.40-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40 does not have the vulnerable LocalFilesystemAdapter class or signed URL generation for local filesystem. The feature was introduced in Laravel 11+ (September 2024), years after this version. The FilesystemAdapter.temporaryUrl() method explicitly throws RuntimeException for local adapters - the feature is unsupported."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03873c12-7951-5f72-ade0-9e2426eb00c6",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90b3508c-ca9b-5738-8c41-5d69d95d7684",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d408ef5-eda4-54b6-a44c-7fffc468ccf4",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-15133 does not affect version 5.5.50-p1+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01547bfc-8108-5864-8e2c-2f24bc76f389",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b6c4fae-b645-5eed-80ce-0a90b77dbee3",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94bed58f-0fca-5ddc-8d4a-51734144d386",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b506cc47-92d7-50d1-a2be-df6d65148122",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05b1504b-773d-5b0b-ad78-0715a0557c1d",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43617 affects version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5909a3d-a4ec-53d6-9d88-04414d58f7b6",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60f56e9-c756-5de0-a824-7bddae1274e2",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.5.50-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c1d3a1e-af34-5845-908a-8a62782a6728",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956292d3-3ed2-53ce-a42f-5f7566d91ea5",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06e5da1-ef1f-5f27-970e-97835240b13c",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de5b4c8e-9d80-5091-8353-ead34eca9254",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.5.50-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90c85e35-a098-5c32-8175-25fc98de62ab",
      "id": "GHSA-6jvx-8ch9-j2jr",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6jvx-8ch9-j2jr does not affect version 5.5.50-p1+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c47338f8-16fe-5ea8-b036-dd1971cb7458",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.5.50-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f31f9e2f-9aa3-520f-b024-eb879ff92cf6",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43be5be6-9ef1-58eb-afc8-f65e3975a9e0",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.5.50-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f40ed1b1-322c-5570-a5dd-f14b42e6a0f2",
      "id": "CVE-2019-9081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-9081 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e51d9de9-2fcb-5dda-8f6b-3267080c1d73",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66784f1a-8e6e-5c9c-a46a-f5ca92df2600",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5947621-3a8e-53a0-8b72-ecb3eaa79a88",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c2e3c85-0538-5ca7-bcb0-93c94880c4a6",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3fd698e-df23-5a46-94ff-50103f43ac9c",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.7.29-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6e393e0-a395-5a90-b60e-d0a3b3e316fc",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee6fddaf-6840-5734-a038-8f2e76708e44",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.7.29-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ba9c8d-4aa3-55c9-a30d-9ff49de2d668",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70b08011-711f-5ab5-a229-095a37a27f78",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0605fc7d-38e3-5908-9435-b35f5d2ce817",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfa9782d-27fc-5d75-8714-6aa277b26d32",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.7.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.7.29 uses SwiftMailer, not Symfony Mailer. The GHSA-5vg9-5847-vvmq vulnerability specifically requires Symfony Mailer's handling of CRLF sequences. SwiftMailer employs EmailValidator which rejects CRLF in email addresses, breaking the attack chain."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:781e46ba-e0bc-5887-ae4d-a9f45edc0bdc",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.7.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.7.29 does not support temporary signed URLs for local filesystem storage. The vulnerable feature (LocalFilesystemAdapter with temporaryUrl/temporaryUploadUrl methods) does not exist in this version. The FilesystemAdapter::temporaryUrl() method explicitly throws RuntimeException when used with LocalAdapter."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cb87620-e30e-5b9f-ac7f-6ac5e289c4da",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26960429-2feb-5305-8b3f-a7fe5759b5ef",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.7.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5609fae0-66b4-524c-8bcb-7d00c9581752",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:722ec2b0-4569-56b0-918b-109994e1b226",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ead0d979-ea6a-59fb-9bdf-e7181d2903a3",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3f44a0-ea92-5ad6-856a-501bc6fe81d2",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7979fe1-9f69-5357-ab94-613bffce7e43",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0146ae6c-2279-57f6-96ec-42a1d8592d8a",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9bb533f-333c-5fa5-b2b7-5eab0608508a",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8dbee8-b3b0-50bb-8bdd-2b38a86f52b6",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd2c6b0-9f9a-5917-8618-e1b0117f6897",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12081543-12a8-5de7-99dd-41986d09777c",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5e51dea-7e5f-53d1-8678-d5335d850c2e",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d78ffa-ad9f-5345-8999-d2356f9ab31c",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:156c584c-b359-53cc-8446-9f55a407ef07",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19640d34-1c25-5906-82b8-96306f853ff8",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd46defd-6ede-5f1a-b4bb-340573adb7b7",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e3def7-fa28-5b79-90c1-707dab25a8e4",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f5fc385-6901-52c5-bd90-2fe84ba4a614",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c79d5586-e3a1-5490-983d-4d46935e0f0a",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p2+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba9921b-84b0-5b39-973d-ef96947440c6",
      "id": "CVE-2024-51736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51736 is fixed in version 3.4.47-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fb2592a-ab05-5df0-a3e6-87ae7f65051f",
      "id": "CVE-2026-24739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24739 is fixed in version 3.4.47-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@3.4.47-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c42abe6-9cba-5558-958e-f388fd8bd2ac",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d24c0314-b3d9-5a3f-b519-124d945739f3",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f102856f-b506-58b6-87f8-31480a80061f",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4f3241a-901f-5fa3-8113-6ed755566948",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84e9a288-a47e-5295-ad3c-41cf1fdc5396",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c781ec07-17e9-5483-b84a-68f75ccaaf33",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a809a5-a665-507c-a5f2-7b4ff41a1247",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64054f20-eb2b-5e63-9b74-56fd1c7c41c6",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786c138c-f822-58d5-8e41-d702aee01b29",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2318791a-6cf0-5862-81bc-b337b0e89e45",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20047200-3c37-530e-8c30-5c8d8af05357",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bac48a7-39c3-5b6d-943b-9557a7097790",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p2+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e54ffdf-4af2-5bad-a2d7-3477dc14de5e",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-14775 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f299e841-e7fc-5626-8efa-2099e1e54eaf",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-16894 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04a038e4-e8a7-5ce0-8750-8736dc4c9ee5",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-15133 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:431c7f45-1203-5e39-93ae-e3e3992ad264",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-19316 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7465776-d57a-5b1c-a834-b79ff348124c",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-24941 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b9912f0-636d-53d1-ad2d-01f119b524e5",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21263 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3676bfbf-790c-54b4-a4fc-0e545cfab616",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e290936a-51ac-50a6-913a-442e5665c5f3",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52301 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1a941ee-8949-5014-9e58-2ba32702a511",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:375a7a5a-3efe-5608-a663-b903964be5f2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b90aa652-27b1-5a80-921d-ac234cc02ed2",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f4643a7-ae71-5ebc-bacf-d926c4b14fa2",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg affects version 5.4.36-p1+tuxcare of illuminate/database."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dddfc75-4fba-5702-8b69-0ad5ac5a9313",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24765 is fixed in version 12.4.5-p1+tuxcare of phpunit/phpunit."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpunit/phpunit@12.4.5-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d290ac5-66ad-5ddf-8a37-d0b1103db40f",
      "id": "CVE-2025-46734",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46734 is fixed in version 1.6.7-p2+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e3f75e3-95eb-5887-b201-d27feb25d4c5",
      "id": "CVE-2026-30838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-30838 affects version 1.6.7-p2+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:765ebd8b-06f9-530f-a98b-6a55b29da0e9",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p2+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a36f16-3c9d-5f6f-80a2-224670d71db0",
      "id": "GHSA-c2pc-g5qf-rfrf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p2+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aed0748-3e5c-5525-b010-1048ce602ae8",
      "id": "CVE-2024-51736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51736 is fixed in version 5.4.45-p2+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@5.4.45-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d528459-9499-5686-bfeb-613d847b9900",
      "id": "CVE-2026-24739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24739 is fixed in version 5.4.45-p2+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@5.4.45-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c11ecfd-36bb-5baf-a856-b169ead16c40",
      "id": "CVE-2024-51736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51736 is fixed in version 4.4.44-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@4.4.44-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67a9e98-f2e7-5898-a661-7e97deaa0dbb",
      "id": "CVE-2026-24739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24739 is fixed in version 4.4.44-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@4.4.44-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e89add-c5e3-56d0-8fa6-94841518d0f2",
      "id": "CVE-2024-51736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51736 is fixed in version 6.4.13-p2+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@6.4.13-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e68ac92-666c-5a1c-be97-e4a64aa5761d",
      "id": "CVE-2026-24739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24739 is fixed in version 6.4.13-p2+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@6.4.13-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fba09520-61c3-5309-aa97-f41783d6ad93",
      "id": "CVE-2014-2681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-2681 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a2e8d8-34db-5469-902c-7bdef7383b44",
      "id": "CVE-2014-2682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-2682 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:882c8f2c-a740-5087-8c11-2b588523a064",
      "id": "CVE-2014-2683",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-2683 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:895d9c31-2dbd-537b-8481-0cbc1b126f9b",
      "id": "CVE-2015-3154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-3154 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59829be9-86ec-5f71-88cc-f0d66931c03f",
      "id": "CVE-2015-5161",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-5161 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb0f702f-0a92-5c64-a921-15a3f194d9a0",
      "id": "CVE-2015-5723",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-5723 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e74e7b8a-3da1-5b4d-8100-7522ef947190",
      "id": "CVE-2015-7695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-7695 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c915821-167b-5a06-97fd-1b3ebb77b3bb",
      "id": "CVE-2016-4861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-4861 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16bbf098-698e-52f9-9654-c6550ad3c8cc",
      "id": "CVE-2016-6233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-6233 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4f52535-3a5c-5f8c-922b-3d750ebb5c9d",
      "id": "GHSA-6fqw-j3vm-7f66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6fqw-j3vm-7f66 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfbd6cf1-9b25-57d1-9008-72d41153e049",
      "id": "GHSA-848f-mph5-9pm9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-848f-mph5-9pm9 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:855b7506-decb-5a6f-9f39-f71839362281",
      "id": "GHSA-8xhv-gqm4-3w99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-8xhv-gqm4-3w99 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9657657b-37ec-5a3b-b9cb-de18235ab73c",
      "id": "GHSA-gff2-p6vm-3p8g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-gff2-p6vm-3p8g is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe983f0-ff1d-58c8-a397-8edc1ec77953",
      "id": "GHSA-v42g-7q2x-cw32",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v42g-7q2x-cw32 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1."
      },
      "affects": [
        {
          "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be127029-89c0-5479-8f1c-38fc4cc66883",
      "id": "CVE-2025-22145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22145 is fixed in version 1.39.1-p1+tuxcare of nesbot/carbon."
      },
      "affects": [
        {
          "ref": "pkg:composer/nesbot/carbon@1.39.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18233dfb-d542-5316-986f-c7a4da16fc41",
      "id": "CVE-2020-13625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-13625 is fixed in version 5.2.28-p1+tuxcare of phpmailer/phpmailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d863f1-ca77-59f7-beed-005b6dbd8c66",
      "id": "CVE-2021-34551",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-34551 is fixed in version 5.2.28-p1+tuxcare of phpmailer/phpmailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03adade4-7a7b-5754-84ff-3016fcd0474f",
      "id": "CVE-2021-3603",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3603 is fixed in version 5.2.28-p1+tuxcare of phpmailer/phpmailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef35376-bbd9-5c11-9f45-3bb3063ba513",
      "id": "CVE-2024-21544",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21544 affects version 4.4.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b88dec2-dde8-5f61-8d6f-b675ddb375dd",
      "id": "CVE-2024-21547",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21547 affects version 4.4.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a019170d-162b-5203-89f8-6f78be11803d",
      "id": "CVE-2024-21549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-21549 affects version 4.4.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4577e146-0bf4-5359-b275-6c2649149246",
      "id": "CVE-2025-1022",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1022 affects version 4.4.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e935e3f0-e1a3-5a6a-bc1f-735c44158216",
      "id": "CVE-2025-1026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1026 affects version 4.4.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ca7642-d1e5-558a-a8cb-1153f84275ab",
      "id": "CVE-2025-3192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3192 is fixed in version 4.4.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac63016a-ebe9-5550-8c48-73d2db3d6663",
      "id": "CVE-2024-21544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21544 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3001aa5-acf3-5664-b017-add65a10ff77",
      "id": "CVE-2024-21547",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21547 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e73aba96-5b27-5255-9db0-c4ed1a59fa0e",
      "id": "CVE-2024-21549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21549 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cdf2210-64ee-57bc-b6e1-65ec0921c09c",
      "id": "CVE-2025-1022",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1022 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dc68d3c-a2dc-5aec-a534-a3fe34d03742",
      "id": "CVE-2025-1026",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1026 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e55ac6e4-3938-5b4a-bc13-e4ad0249a2ef",
      "id": "CVE-2025-3192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3192 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1e53763-5200-52d4-9f35-83efb2e1f09a",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p1+tuxcare of illuminate/view."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb8f8b95-ab84-552f-a68e-af561994d473",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p1+tuxcare of illuminate/view."
      },
      "affects": [
        {
          "ref": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc4a21ee-eaa5-5af6-9534-c18927776d1b",
      "id": "CVE-2023-51651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-51651 is fixed in version 3.263.4-p1+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfbe3927-be59-5fb0-b2da-c461df750a2c",
      "id": "CVE-2025-14761",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14761 affects version 3.263.4-p1+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07060541-204d-56e0-b515-78bbc0c7c5c1",
      "id": "GHSA-27qh-8cxx-2cr5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-27qh-8cxx-2cr5 affects version 3.263.4-p1+tuxcare of aws/aws-sdk-php."
      },
      "affects": [
        {
          "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab3e88b-29da-561b-9cb3-1be90554a6fa",
      "id": "AIKIDO-2025-10963",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability AIKIDO-2025-10963 does not affect version 6.11.1-p2+tuxcare of firebase/php-jwt. already_fixed \u2014 The target repository firebase/php-jwt version 6.11.1 has already been fixed for AIKIDO-2025-10963 (Inadequate Encryption Strength). TuxCare applied an identical backport in commit 9d756cb (PHPELSCVE-211) that implements the same key length validation as the upstream patch."
      },
      "affects": [
        {
          "ref": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bece65f-b8a3-5f56-988c-e767f93ec7bd",
      "id": "CVE-2025-45769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-45769 is fixed in version 6.11.1-p2+tuxcare of firebase/php-jwt."
      },
      "affects": [
        {
          "ref": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4f313d2-d291-54c6-8d11-0a33d8b571c6",
      "id": "CVE-2015-8379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-8379 is fixed in version 2.10.24-p1+tuxcare of cakephp/cakephp."
      },
      "affects": [
        {
          "ref": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf19e6a4-d297-5355-9f33-61f6105873d6",
      "id": "CVE-2020-15400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-15400 is fixed in version 2.10.24-p1+tuxcare of cakephp/cakephp."
      },
      "affects": [
        {
          "ref": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d3bedf3-fb59-5f60-a21a-24b321e1a22f",
      "id": "CVE-2026-48820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48820 affects version 2.10.24-p1+tuxcare of cakephp/cakephp."
      },
      "affects": [
        {
          "ref": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd6ec9a8-f7ff-58b9-a09d-d0da948700b3",
      "id": "CVE-2024-21544",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21544 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74a518ec-50fe-5000-a775-f184f5306221",
      "id": "CVE-2024-21547",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21547 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b17c5ab-44dd-5017-bcd4-23b645b4f478",
      "id": "CVE-2024-21549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21549 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf6b0457-5f8c-548b-af72-1722e1425cb3",
      "id": "CVE-2025-1022",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1022 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc96502-d3d2-5846-b80f-f9e8b85460e6",
      "id": "CVE-2025-1026",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-1026 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ff60695-c00f-588e-ae16-92476611e387",
      "id": "CVE-2025-3192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3192 affects version 3.61.0-p1+tuxcare of spatie/browsershot."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e1ad2ee-1935-56ff-ad0d-4c6f91574c0f",
      "id": "AIKIDO-2025-10963",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability AIKIDO-2025-10963 does not affect version 6.11.1-p1+tuxcare of firebase/php-jwt. already_fixed \u2014 The target repository firebase/php-jwt version 6.11.1 has already been fixed for AIKIDO-2025-10963 (Inadequate Encryption Strength). TuxCare applied an identical backport in commit 9d756cb (PHPELSCVE-211) that implements the same key length validation as the upstream patch."
      },
      "affects": [
        {
          "ref": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa6f7419-cbc8-5295-8995-e632fe1e1a98",
      "id": "CVE-2025-45769",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-45769 affects version 6.11.1-p1+tuxcare of firebase/php-jwt."
      },
      "affects": [
        {
          "ref": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0edfcc10-c29b-5b30-8ef0-d59f8d4ae7d9",
      "id": "AIKIDO-2024-10189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10189 is fixed in version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2943af3e-8bbb-5172-b93f-88e0c7e45b7d",
      "id": "CVE-2026-48555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48555 affects version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b8361cc-a790-5893-b0c6-de413fd89faf",
      "id": "CVE-2026-48557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48557 affects version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:506640c9-1ef5-5de6-9904-9a7ff74da37e",
      "id": "AIKIDO-2024-10189",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10189 is fixed in version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09449381-9704-58bf-8941-f832c001b502",
      "id": "CVE-2026-48555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48555 affects version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60b37bc3-a4ff-5d7e-a3c5-f9f354e6caa1",
      "id": "CVE-2026-48557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48557 affects version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary."
      },
      "affects": [
        {
          "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3707cb40-8020-548e-8614-e0ac64d435d9",
      "id": "CVE-2025-54370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54370 is fixed in version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb12f11-937b-5ec9-b1bf-7c8d8fc06441",
      "id": "CVE-2026-34084",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34084 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8737d12e-76d5-59c5-b88e-7af694dd5bfa",
      "id": "CVE-2026-35453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-35453 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8f3c74a-a7c4-5369-918b-bc64153946ef",
      "id": "CVE-2026-40296",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40296 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c68c48b-da60-5249-8c25-c7297d466d68",
      "id": "CVE-2026-40863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40863 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd935ff1-4e57-5fc7-ae2c-019f1f8ca43f",
      "id": "CVE-2026-40902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40902 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01711593-7c14-5421-ab7b-9415ccee65a8",
      "id": "CVE-2026-59931",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59931 does not affect version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet. not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do..."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03c3d6a-0379-501c-843f-368426dad4fa",
      "id": "CVE-2026-59932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59932 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9034b24-4462-5bbf-ac78-00aea19d3739",
      "id": "CVE-2026-59933",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59933 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5e8dbf-d6e7-5176-98df-39c85893cd94",
      "id": "AIKIDO-2025-10705",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10705 is fixed in version 10.11.4-p1+tuxcare of yajra/laravel-datatables-oracle."
      },
      "affects": [
        {
          "ref": "pkg:composer/yajra/laravel-datatables-oracle@10.11.4-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4c76f80-9dac-5929-acef-a672cdb81536",
      "id": "CVE-2016-10074",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-10074 does not affect version 5.4.12-p1+tuxcare of swiftmailer/swiftmailer. already_fixed \u2014 CVE-2016-10074 has already been fixed in target version 5.4.12. The vulnerability allowed command injection via backslash double quote sequences in email addresses. The fix is explicitly present in Swift_Transport_MailTransport class with the _isShellSafe() validation method that blocks shell-unsafe characters including backslash and double quote before passing email addresses to the mail() com..."
      },
      "affects": [
        {
          "ref": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7a6f984-8ca3-5489-a16d-d34acfb309d4",
      "id": "CVE-2024-28859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28859 is fixed in version 5.4.12-p1+tuxcare of swiftmailer/swiftmailer."
      },
      "affects": [
        {
          "ref": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea17e569-bf3e-5046-9b7e-d497a28a39f3",
      "id": "AIKIDO-2025-10705",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10705 is fixed in version 9.21.2-p1+tuxcare of yajra/laravel-datatables-oracle."
      },
      "affects": [
        {
          "ref": "pkg:composer/yajra/laravel-datatables-oracle@9.21.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a9d6bb-6f18-567e-bc7d-aac5864b7722",
      "id": "CVE-2025-64500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64500 is fixed in version 2.8.52-p1+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:179138a2-f5fe-55b1-bc34-a123cc53b3dc",
      "id": "CVE-2017-14775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-14775 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72b09ac0-11eb-55fc-a95e-cf063c2d1af8",
      "id": "CVE-2017-16894",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-16894 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fa806ae-c838-5385-8189-b878b5a6e324",
      "id": "CVE-2018-15133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-15133 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6eae3a-1f8a-55be-b601-58d5d682ac1a",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-19316 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f35ebbb8-a2a7-54eb-8b5b-c83b80c2a80c",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-24941 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3c97975-55d0-51e7-9657-d513f6c27067",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21263 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c9102a8-bec8-555c-b2ab-ccb1b7743c0b",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0daa222-5be9-5b24-8445-6e797fd2c414",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baf44211-e71f-5c98-9221-3c474ee34903",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcdbeeb8-9e9c-57ed-a32c-648384fa4586",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:722eccce-1c62-58ec-a3ad-eeb0bd8f170d",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52301 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ca8621-ac1e-5e96-8ce5-8069e26b1612",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:691274f3-c015-55f3-80f1-d0b4d7c64ebd",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43515716-97e6-59dc-8c47-ea706c613b39",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c3459aa-03f9-5def-89d6-e871691f0597",
      "id": "GHSA-7852-w36x-6mf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7852-w36x-6mf6 affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe81ba27-4e1c-5802-9290-d68bb9da848a",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad02d2d-0863-5e32-a0f5-b414220d5359",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef996d2f-08e4-5532-8a6e-56760ff30f51",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg affects version 5.4.36-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d93cd7af-aec7-5910-aca0-16a6d91fe94c",
      "id": "CVE-2024-50345",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-50345 affects version 4.4.49-p1+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e1c11da-4abc-518b-8081-8fadfe95364c",
      "id": "CVE-2025-64500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64500 is fixed in version 4.4.49-p1+tuxcare of symfony/http-foundation."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd655cfb-1462-5cca-8281-7f2e1ad7f992",
      "id": "CVE-2021-3838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3838 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49efd1d8-b7f7-5795-a15d-05ac3604350a",
      "id": "CVE-2021-3902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3902 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b0b1c43-90c3-57a0-8bed-645e25aafc08",
      "id": "CVE-2022-0085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-0085 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badadf16-ad1c-5730-9811-f3be04d84a70",
      "id": "CVE-2022-2400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2400 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0eaf181-476d-5ce3-8f35-39bf1f9d5282",
      "id": "CVE-2022-28368",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28368 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6871bebc-a61a-592d-a996-0153b34ae832",
      "id": "CVE-2022-41343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41343 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca4cc82d-a54f-580f-9229-c957fef5cd62",
      "id": "CVE-2023-23924",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23924 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e3c35b-d39b-5a8e-af12-97a6cbd168c5",
      "id": "CVE-2023-50262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50262 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94e777c3-5619-5b57-b20a-a905cff669ac",
      "id": "CVE-2026-55554",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55554 affects version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:457a9362-0890-5d55-87ee-544b994a497b",
      "id": "CVE-2026-55555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55555 affects version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6d0b029-916c-52c4-9490-609a6cd1b94f",
      "id": "CVE-2026-56722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56722 affects version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5951960-7524-50ac-8caf-ac132841c775",
      "id": "CVE-2026-59941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59941 affects version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20276221-e4e2-54b2-b190-b79d86bd8cd3",
      "id": "CVE-2026-59942",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59942 affects version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:741dae05-ca77-5d15-9f0c-42ad7f40447d",
      "id": "CVE-2026-59943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59943 affects version 0.8.6-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b64ccca-0ad3-5c7a-9559-df137cd68bd8",
      "id": "CVE-2025-46734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46734 affects version 1.6.7-p1+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1432c14-4888-53c4-81e4-324b465ecd05",
      "id": "CVE-2026-30838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-30838 affects version 1.6.7-p1+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02c645f-c9d1-5f69-9d4b-99c7b21ad900",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p1+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6739c2d3-c6c4-5347-a571-66aaf31fdfe2",
      "id": "GHSA-c2pc-g5qf-rfrf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p1+tuxcare of league/commonmark."
      },
      "affects": [
        {
          "ref": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e0a7c6-b291-53af-9ae7-ffe6fcb14c24",
      "id": "CVE-2021-3838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3838 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7577a525-2f91-5f6e-b753-fcc83e9d2d62",
      "id": "CVE-2021-3902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-3902 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d4e25ad-23f3-555b-8b41-eb426e862a73",
      "id": "CVE-2022-0085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-0085 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af99000a-2cc2-5dcb-8d7f-c7b1b2c8c7ea",
      "id": "CVE-2022-2400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2400 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf36b977-bf4b-5eae-8136-5cd6f4be22c4",
      "id": "CVE-2022-28368",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-28368 does not affect version 1.2.2-p1+tuxcare of dompdf/dompdf. already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17adc8e-caea-514c-8813-11ab337ca173",
      "id": "CVE-2022-41343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41343 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95bdca01-f34b-57e9-97ad-68e47705bf58",
      "id": "CVE-2023-23924",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23924 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b238dc92-2358-569f-b4f9-e4ec83084a7a",
      "id": "CVE-2023-50262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50262 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e18c851-ad6f-5551-9856-90bb5fe45347",
      "id": "CVE-2026-55554",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55554 affects version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899914c5-c64a-5479-b9f5-2adce86b4b9f",
      "id": "CVE-2026-55555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55555 affects version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a91956-5501-5a88-ab36-005090c47da9",
      "id": "CVE-2026-56722",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56722 affects version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5fdc870-bf4c-5c63-8e82-89c8a1b15e84",
      "id": "CVE-2026-59941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59941 affects version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb825022-2cb9-5a51-be1e-a06b51312c3b",
      "id": "CVE-2026-59942",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59942 affects version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31c376da-7a9d-509b-a900-375933635646",
      "id": "CVE-2026-59943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59943 affects version 1.2.2-p1+tuxcare of dompdf/dompdf."
      },
      "affects": [
        {
          "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e62a47-6337-5927-a461-df2b11485dc2",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2026-10659 affects version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a1bb184-f9be-514d-8505-cefa7de545c2",
      "id": "CVE-2019-9081",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2019-9081 is a false positive for laravel/framework 5.8.38-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:616ee585-6fb7-537a-84b8-dbaa769f6d53",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d521c0dd-de8a-5da5-9b64-be7944efaf14",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.8.38-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b2cc96-0341-559f-9728-f395bb978728",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6b2f174-41ca-5d73-93f0-520fe9fb6c76",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52301 affects version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bbab66d-f770-5d70-b6fc-15978c511de5",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27515 affects version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:984fb0b6-3e55-5ed9-a502-d616110a941d",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a02502-8e1a-55e0-b133-aab1162fd8c4",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308351c8-5efc-5252-8cfb-fc4ffc921886",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8cd309c-7524-525c-ae14-17fa700849a8",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b94ea7f3-f92d-5510-9da0-a489fb455c97",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a65c8b78-8460-53e4-8444-b4220c7d323b",
      "id": "CVE-2025-54068",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54068 is fixed in version 3.6.3-p1+tuxcare of livewire/livewire."
      },
      "affects": [
        {
          "ref": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:659cf3ec-a0e5-5e64-97fc-3ecb41790f64",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 11.44.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c0e08f4-0f64-5367-84aa-f284ce0fb2c2",
      "id": "CVE-2026-24765",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-24765 does not affect version 11.44.0-p1+tuxcare of laravel/framework. CVE-2026-24765 pertains to phpunit, not laravel/framework. Tracked on the phpunit VPV."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71093e1f-9ac6-5b26-8aea-fe291e9a89c7",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 11.44.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b961646-a3c7-5bdb-8b3c-d4f0aacc1142",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 11.44.0-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15289359-2223-542a-b890-16d0bd7d90a2",
      "id": "AIKIDO-2026-10659",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2026-10659 affects version 8.83.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52c36403-b51b-51d1-9323-4935eab60ed9",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f17705-7451-53f7-9718-7c21eed53d43",
      "id": "CVE-2024-36610",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-36610 is a false positive for laravel/framework 8.83.29-p1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6f50b53-6482-5e85-8c70-74be2f2b8be0",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd18f0d4-32fe-5537-8f4f-e7e5b0810042",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.83.29-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:017f94e2-41ed-5a11-8948-ede4dd1b9728",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edb52621-b07f-5aa9-8f91-c7d5c3562475",
      "id": "CVE-2024-51736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51736 is fixed in version 5.4.45-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@5.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74b71b33-811b-5f0b-ad5c-c4cbdee9a8ad",
      "id": "CVE-2026-24739",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24739 affects version 5.4.45-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@5.4.45-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700c815e-4f60-5106-8b47-84ebd40c2406",
      "id": "CVE-2024-51736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-51736 is fixed in version 6.4.13-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@6.4.13-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1b96dbd-efbf-5292-88fd-c4d8574cc95b",
      "id": "CVE-2026-24739",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24739 affects version 6.4.13-p1+tuxcare of symfony/process."
      },
      "affects": [
        {
          "ref": "pkg:composer/symfony/process@6.4.13-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3813e437-a062-507a-9078-ac25525315f0",
      "id": "CVE-2025-22145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22145 is fixed in version 1.26.6-p1+tuxcare of nesbot/carbon."
      },
      "affects": [
        {
          "ref": "pkg:composer/nesbot/carbon@1.26.6-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/ratchet/pawl@v0.1.2-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/voryx/thruway@0.4.2-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
    },
    {
      "ref": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/cboden/ratchet@v0.3.6-p4+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/monolog/monolog@1.11.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/voryx/thruway@0.4.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/ratchet/pawl@v0.1.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
    },
    {
      "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/http-kernel@v7.4.10-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laminas/laminas-http@2.5.6-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/mailer@v6.4.34-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
    },
    {
      "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/http-kernel@v3.4.49-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/mailer@v7.4.8-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laminas/laminas-diactoros@2.22.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/cboden/ratchet@v0.3.6-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/cboden/ratchet@v0.3.6-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@4.8.10-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/cboden/ratchet@v0.3.6-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/league/flysystem@1.0.70-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/league/flysystem@1.1.10-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/doctrine/orm@2.8.3-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@8.4.3-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@7.5.20-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@9.5.28-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@6.5.14-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@10.4.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
    },
    {
      "ref": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@11.4.4-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/process@3.4.47-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpunit/phpunit@12.4.5-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/process@5.4.45-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/process@4.4.44-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/process@6.4.13-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/nesbot/carbon@1.39.1-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare"
    },
    {
      "ref": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/yajra/laravel-datatables-oracle@10.11.4-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/yajra/laravel-datatables-oracle@9.21.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/process@5.4.45-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/symfony/process@6.4.13-p1+tuxcare"
    },
    {
      "ref": "pkg:composer/nesbot/carbon@1.26.6-p1+tuxcare"
    }
  ]
}