{
  "@id": "urn:uuid:995d265c-d314-4ab0-adc6-7ea8c07dcf77",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T20:27:02.675922+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 8.83.29-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p3+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T20:27:02.675922+00:00",
      "status_notes": "Vulnerability CVE-2026-102279 does not affect version 8.83.29-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by CVE-2026-102279. The vulnerability exists in the new exception renderer with Tippy.js tooltips (allowHTML: true) introduced in Laravel 12.x. The target version uses Whoops library's PrettyPageHandler for debug exception rendering instead, which does not have Tippy.js or any tooltip system that could be exploited via attacker-controlled HTML content.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102279"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.83.29 is not affected by CVE-2026-102279. The vulnerability exists in the new exception renderer with Tippy.js tooltips (allowHTML: true) introduced in Laravel 12.x. The target version uses Whoops library's PrettyPageHandler for debug exception rendering instead, which does not have Tippy.js or any tooltip system that could be exploited via attacker-controlled HTML content."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.83.29-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
    }
  ]
}
