{
  "@id": "urn:uuid:8596c0d4-2234-4f00-8cc7-09f8853044c0",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T20:17:00.109653+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-14775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-16894"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2018-15133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T20:17:00.109653+00:00",
      "status_notes": "Vulnerability CVE-2026-102279 does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 does not contain the vulnerable code. The CVE-2026-102279 vulnerability affects Laravel's custom exception renderer with Tippy.js tooltips (introduced in Laravel 11.x circa 2024). Version 5.4.36 (2017) uses Symfony's SymfonyExceptionHandler v3.4.47 for exception rendering, which does not use JavaScript tooltips and properly escapes all dynamic content via htmlspecialchars(). The ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102279"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 does not contain the vulnerable code. The CVE-2026-102279 vulnerability affects Laravel's custom exception renderer with Tippy.js tooltips (introduced in Laravel 11.x circa 2024). Version 5.4.36 (2017) uses Symfony's SymfonyExceptionHandler v3.4.47 for exception rendering, which does not use JavaScript tooltips and properly escapes all dynamic content via htmlspecialchars(). The ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      },
      "action_statement": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch...",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-7852-w36x-6mf6"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      },
      "action_statement": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    }
  ]
}
