{
  "@id": "urn:uuid:7aee4675-9ef4-45a4-9283-f7f9ea84030e",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 3,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-29T20:36:58.499788+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 9.52.21-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T20:36:58.499788+00:00",
      "status_notes": "Vulnerability CVE-2026-102279 does not affect version 9.52.21-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by CVE-2026-102279. The vulnerability concerns XSS via Tippy.js tooltips with allowHTML:true in Laravel 12.x's new exception renderer component. This component does not exist in Laravel 9.52.21, which uses Whoops or Symfony's HtmlErrorRenderer for exception display instead. Exhaustive searches found no tippy.js, allowHTML, or formatted-source.blade.php in the tar...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-102279"
      },
      "impact_statement": "not_affected \u2014 Laravel 9.52.21 is not affected by CVE-2026-102279. The vulnerability concerns XSS via Tippy.js tooltips with allowHTML:true in Laravel 12.x's new exception renderer component. This component does not exist in Laravel 9.52.21, which uses Whoops or Symfony's HtmlErrorRenderer for exception display instead. Exhaustive searches found no tippy.js, allowHTML, or formatted-source.blade.php in the tar..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 9.52.21-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
    }
  ]
}
