{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ad214d78-f63a-51b3-88e1-cffbde0d700d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "parsedown",
      "purl": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare",
      "type": "library",
      "group": "erusev",
      "bom-ref": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare",
      "version": "1.6.4-p1+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2018-1000162",
      "affects": [
        {
          "ref": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4c3add90-5ff4-5f6f-bb1b-bb38e74b9f27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1000162 is fixed in version 1.6.4-p1+tuxcare of erusev/parsedown."
      }
    },
    {
      "id": "CVE-2019-10905",
      "affects": [
        {
          "ref": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0048c937-ade1-51e1-9352-0aeae79e6965",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-10905 does not affect version 1.6.4-p1+tuxcare of erusev/parsedown. Version 1.6.x is NOT affected by CVE-2019-10905. The vulnerability exists only in versions 1.7.0\u20131.7.1 which used a permissive regex pattern ([^`]+)? that captures spaces in code fence infostrings. Version 1.6.x uses the restrictive pattern ([\\w-]+)? that rejects lines with spaces, preventing the attack chain from completing. The regex at line 399 fails to match infostrings like \"javascript extra\", so no code block is created and no class injection occurs. Python regex testing confirms this behavior. The patch commit message \"[1.7.x] Fix spaces in class names\" indicates the fix targets the 1.7.x branch specifically.",
        "justification": "code_not_reachable"
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare"
    }
  ]
}