{
  "@id": "urn:uuid:b19a0e93-3fec-4b6a-b131-70e0b1b389c3",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T20:33:09.068963+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 10.50.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T20:33:09.068963+00:00",
      "status_notes": "Vulnerability CVE-2026-102279 does not affect version 10.50.2-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.50.2 is not affected by CVE-2026-102279. The vulnerability exists in Laravel 12.x's new exception renderer feature that uses Tippy.js tooltips with allowHTML:true. Laravel 10.x uses a completely different exception handling system (Whoops library) and does not contain the vulnerable code pattern. The exception renderer with Tippy.js was introduced in Laravel 12.x and does not exist i...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102279"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.50.2 is not affected by CVE-2026-102279. The vulnerability exists in Laravel 12.x's new exception renderer feature that uses Tippy.js tooltips with allowHTML:true. Laravel 10.x uses a completely different exception handling system (Whoops library) and does not contain the vulnerable code pattern. The exception renderer with Tippy.js was introduced in Laravel 12.x and does not exist i..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.50.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.50.2-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version."
    }
  ]
}
