{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9b63cbb9-b28d-5ee9-87e3-489460e9fe73",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "8.12.0-p4+tuxcare",
      "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:32a1fc31-b757-5c25-8c9f-16449639f81d",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87af5a40-ac30-5ce3-9398-f7480be67a17",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:577f4143-07a2-58f2-b404-ef2e928e5ca6",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a69cd3-e5e7-5306-912f-5b1fccfe5c40",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ef122d-186b-5a94-ac4a-25042ce3671a",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bc40af2-aad4-5f5f-bc61-18d9c30e0efd",
      "id": "CVE-2026-33347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p4+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cfb1a54-9987-516e-aa14-1c7682c09afb",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:637383fa-37a5-5fcf-9537-6e8aac4adbb0",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e51a1470-cfae-5b9d-badf-86e15a2bb6c8",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b635a218-e867-59a1-b5b3-48e2da28abac",
      "id": "GHSA-jwvj-pwww-3mj5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c106a810-815c-5741-b387-c479fe60724f",
      "id": "GHSA-wq8p-mqvg-2p5h",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc082e77-c259-5e4c-90e5-1563b5748019",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p4+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
    }
  ]
}