{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "author": "https://tuxcare.com",
  "role": "Document Creator",
  "timestamp": "2026-09-24T14:43:41.647513+00:00",
  "version": 1,
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      },
      "action_statement": "Vulnerability CVE-2021-43808 affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      },
      "action_statement": "Vulnerability CVE-2024-52301 affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p1+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      },
      "action_statement": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      },
      "action_statement": "Vulnerability GHSA-wq8p-mqvg-2p5h affects version 8.12.0-p1+tuxcare of laravel/framework, and is fixed in 8.12.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p3+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.0-p3+tuxcare of laravel/framework, and is fixed in 8.12.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.0-p3+tuxcare of laravel/framework, and is fixed in 8.12.0-p4+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 is fixed in version 6.0.2-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      },
      "action_statement": "Vulnerability CVE-2026-55568 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      },
      "action_statement": "Vulnerability CVE-2026-55767 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p3+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-view@2.1.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-view@2.1.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-m7hr-j867-3f34 is fixed in version 2.1.6-p1+tuxcare of zendframework/zend-view.",
      "vulnerability": {
        "name": "GHSA-m7hr-j867-3f34"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 is fixed in version 2.8.2-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 is fixed in version 2.8.2-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f8fg-pg57-v4j8 affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f8fg-pg57-v4j8"
      },
      "action_statement": "Vulnerability GHSA-f8fg-pg57-v4j8 affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph is fixed in version 2.8.2-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf is fixed in version 2.8.2-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 2.8.2-p2+tuxcare of league/commonmark, and is fixed in 2.8.2-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mh25-x5hq-wrqp is fixed in version 2.8.2-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mh25-x5hq-wrqp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mj63-m3rc-8ppr is fixed in version 2.8.2-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mj63-m3rc-8ppr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 is fixed in version v2.8.52-p3+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 is fixed in version v2.8.52-p3+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v2.8.52-p3+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10189 is fixed in version 9.12.4-p2+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "AIKIDO-2024-10189"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48555 is fixed in version 9.12.4-p2+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "CVE-2026-48555"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48557 is fixed in version 9.12.4-p2+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "CVE-2026-48557"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3007 is fixed in version 2.4.13-p1+tuxcare of zendframework/zendframework.",
      "vulnerability": {
        "name": "CVE-2021-3007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fh7r-58q4-6387 affects version 2.4.13-p1+tuxcare of zendframework/zendframework.",
      "vulnerability": {
        "name": "GHSA-fh7r-58q4-6387"
      },
      "action_statement": "Vulnerability GHSA-fh7r-58q4-6387 affects version 2.4.13-p1+tuxcare of zendframework/zendframework."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework@2.4.13-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g does not affect version 2.4.13-p1+tuxcare of zendframework/zendframework. GHSA-gff2-p6vm-3p8g is fixed in 2.4.11 (per https://github.com/advisories/GHSA-gff2-p6vm-3p8g); this VPV targets 2.4.13 which already includes the fix \u2014 not affected.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      },
      "impact_statement": "GHSA-gff2-p6vm-3p8g is fixed in 2.4.11 (per https://github.com/advisories/GHSA-gff2-p6vm-3p8g); this VPV targets 2.4.13 which already includes the fix \u2014 not affected."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48998 is fixed in version 1.9.1-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-48998"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49214 is fixed in version 1.9.1-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-49214"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55766 is fixed in version 1.9.1-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-55766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59882 is fixed in version 1.9.1-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-59882"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/google/protobuf@3.24.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6409 is fixed in version 3.24.4-p1+tuxcare of google/protobuf.",
      "vulnerability": {
        "name": "CVE-2026-6409"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21544 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21544"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21547 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21547"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21549 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21549"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1022 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-1022"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1026 is fixed in version 3.61.0-p1+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-1026"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3192 affects version 3.61.0-p1+tuxcare of spatie/browsershot, and is fixed in 3.61.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-3192"
      },
      "action_statement": "Vulnerability CVE-2025-3192 affects version 3.61.0-p1+tuxcare of spatie/browsershot, and is fixed in 3.61.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.2-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is a false positive for laravel/framework 8.12.2-p1+tuxcare. false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l...",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.2-p1+tuxcare of laravel/framework, and is fixed in 8.12.2-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.2-p1+tuxcare of laravel/framework, and is fixed in 8.12.2-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.2-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p5+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 12.58.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 12.58.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp is fixed in version 12.58.0-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 is fixed in version 2.7.1-p1+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is fixed in version 2.7.1-p1+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      },
      "action_statement": "Vulnerability CVE-2026-71478 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      },
      "action_statement": "Vulnerability CVE-2026-71488 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f8fg-pg57-v4j8 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f8fg-pg57-v4j8"
      },
      "action_statement": "Vulnerability GHSA-f8fg-pg57-v4j8 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      },
      "action_statement": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      },
      "action_statement": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mh25-x5hq-wrqp affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-mh25-x5hq-wrqp"
      },
      "action_statement": "Vulnerability GHSA-mh25-x5hq-wrqp affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mj63-m3rc-8ppr affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-mj63-m3rc-8ppr"
      },
      "action_statement": "Vulnerability GHSA-mj63-m3rc-8ppr affects version 2.7.1-p1+tuxcare of league/commonmark, and is fixed in 2.7.1-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-45440"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      },
      "action_statement": "Vulnerability CVE-2025-13080 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      },
      "action_statement": "Vulnerability CVE-2025-13081 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      },
      "action_statement": "Vulnerability CVE-2025-13082 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      },
      "action_statement": "Vulnerability CVE-2025-13083 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      },
      "action_statement": "Vulnerability CVE-2026-6366 affects version 9.5.11-p3+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6CCV-8FGF-CJPW"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p3+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      },
      "impact_statement": "already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 7.10.0-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 7.10.0-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 7.10.0-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 7.10.0-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 7.10.0-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      },
      "action_statement": "Vulnerability CVE-2022-29248 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.0.2-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      },
      "action_statement": "Vulnerability CVE-2022-31090 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      },
      "action_statement": "Vulnerability CVE-2022-31091 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      },
      "action_statement": "Vulnerability CVE-2026-55568 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      },
      "action_statement": "Vulnerability CVE-2026-55767 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products.",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab...",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th...",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron...",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n...",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t...",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core...",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra...",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil...",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p1+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do...",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p1+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.3-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.3-p1+tuxcare of laravel/framework, and is fixed in 8.12.3-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.3-p1+tuxcare of laravel/framework, and is fixed in 8.12.3-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.3-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.3-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      },
      "action_statement": "Vulnerability CVE-2025-13081 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      },
      "action_statement": "Vulnerability CVE-2025-13082 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      },
      "action_statement": "Vulnerability CVE-2025-13083 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      },
      "action_statement": "Vulnerability CVE-2025-3057 affects version 8.9.20-p1+tuxcare of drupal/core, and is fixed in 8.9.20-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7809 does not affect version v2.15.6-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is running Twig 2.15.6, which is significantly newer than the vulnerable versions. The security fix that prevents arbitrary code execution via the _self variable in Sandbox mode is present in the target code at src/Template.php lines 175-178, with explicit documentation ('avoid RCEs when sandbox is enabled') and test coverage.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2015-7809"
      },
      "impact_statement": "already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is running Twig 2.15.6, which is significantly newer than the vulnerable versions. The security fix that prevents arbitrary code execution via the _self variable in Sandbox mode is present in the target code at src/Template.php lines 175-178, with explicit documentation ('avoid RCEs when sandbox is enabled') and test coverage."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-9942 does not affect version v2.15.6-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 was fixed in Twig version 2.7.0 (released 2019-03-12). The target version 2.15.6 (released 2023-11-21) already contains the complete fix. The vulnerability allowed calling __toString() on objects in sandbox mode even when not allowed by the security policy. The fix introduces ensureToStringAllowed() method and CheckToStringNode wrapping mechanism that validates all implicit __toSt...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2019-9942"
      },
      "impact_statement": "already_fixed \u2014 CVE-2019-9942 was fixed in Twig version 2.7.0 (released 2019-03-12). The target version 2.15.6 (released 2023-11-21) already contains the complete fix. The vulnerability allowed calling __toString() on objects in sandbox mode even when not allowed by the security policy. The fix introduces ensureToStringAllowed() method and CheckToStringNode wrapping mechanism that validates all implicit __toSt..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45411 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-45411"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51754 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51755 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51755"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46628 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46633 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46633"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46635 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46638 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47732 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-47732"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48805 does not affect version v2.15.6-p2+tuxcare of twig/twig. not_affected \u2014 Twig v2.15.6 is not affected by CVE-2026-48805. The vulnerability exists only in Twig 3.26.0+ where architectural changes introduced deprecated wrapper functions in src/Resources/core.php that fail to forward sandbox state to CoreExtension methods. This architectural pattern does not exist in v2.15.6, which uses a different implementation where sandbox enforcement is correctly handled.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48805"
      },
      "impact_statement": "not_affected \u2014 Twig v2.15.6 is not affected by CVE-2026-48805. The vulnerability exists only in Twig 3.26.0+ where architectural changes introduced deprecated wrapper functions in src/Resources/core.php that fail to forward sandbox state to CoreExtension methods. This architectural pattern does not exist in v2.15.6, which uses a different implementation where sandbox enforcement is correctly handled."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48806 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48806"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48807 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48807"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48808 does not affect version v2.15.6-p2+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48808 does not affect Twig 2.15.6 because it specifically targets a vulnerability in sandboxing enabled through SourcePolicyInterface, which does not exist in this version. The target uses a fundamentally different architecture predating the SourcePolicyInterface feature.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48808"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-48808 does not affect Twig 2.15.6 because it specifically targets a vulnerability in sandboxing enabled through SourcePolicyInterface, which does not exist in this version. The target uses a fundamentally different architecture predating the SourcePolicyInterface feature."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49981 is fixed in version v2.15.6-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-49981"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-GCFG-HMWX-WQ5H is fixed in version 0.3.2-p1+tuxcare of nategood/httpful.",
      "vulnerability": {
        "name": "GHSA-GCFG-HMWX-WQ5H"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/nategood/httpful@0.3.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gcfg-hmwx-wq5h does not affect version 0.3.2-p1+tuxcare of nategood/httpful. already_fixed \u2014 The target repository (nategood/httpful v0.3.2-p1+tuxcare) already contains the security fix for GHSA-gcfg-hmwx-wq5h. The vulnerability was that SSL/TLS certificate validation was disabled by default (strict_ssl = false), allowing man-in-the-middle attacks. The fix changes the default to strict_ssl = true, enabling certificate validation. TuxCare backported this fix in commit 588532c on 2026-05...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-gcfg-hmwx-wq5h"
      },
      "impact_statement": "already_fixed \u2014 The target repository (nategood/httpful v0.3.2-p1+tuxcare) already contains the security fix for GHSA-gcfg-hmwx-wq5h. The vulnerability was that SSL/TLS certificate validation was disabled by default (strict_ssl = false), allowing man-in-the-middle attacks. The fix changes the default to strict_ssl = true, enabling certificate validation. TuxCare backported this fix in commit 588532c on 2026-05..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50251 is fixed in version 0.3.4-p1+tuxcare of phenx/php-svg-lib.",
      "vulnerability": {
        "name": "CVE-2023-50251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-25117 is fixed in version 0.3.4-p1+tuxcare of phenx/php-svg-lib.",
      "vulnerability": {
        "name": "CVE-2024-25117"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phenx/php-svg-lib@0.3.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-97m3-52wr-xvv2 is fixed in version 0.3.4-p1+tuxcare of phenx/php-svg-lib.",
      "vulnerability": {
        "name": "GHSA-97m3-52wr-xvv2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/spamspan@7.1.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/spamspan@7.1.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31687 is fixed in version 7.1.4-p1+tuxcare of drupal/spamspan.",
      "vulnerability": {
        "name": "CVE-2025-31687"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 is fixed in version v4.4.45-p1+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 affects version v4.4.45-p1+tuxcare of symfony/yaml, and is fixed in v4.4.45-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      },
      "action_statement": "Vulnerability CVE-2026-45304 affects version v4.4.45-p1+tuxcare of symfony/yaml, and is fixed in v4.4.45-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v4.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v4.4.45-p1+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.3.3-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 6.3.3-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/google/protobuf@3.25.9-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/google/protobuf@3.25.9-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6409 is fixed in version 3.25.9-p1+tuxcare of google/protobuf.",
      "vulnerability": {
        "name": "CVE-2026-6409"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/access_code@7.1.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/access_code@7.1.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3129 is fixed in version 7.1.1-p1+tuxcare of drupal/access_code.",
      "vulnerability": {
        "name": "CVE-2025-3129"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/enshrined/svg-sanitize@0.16.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/enshrined/svg-sanitize@0.16.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55166 is fixed in version 0.16.0-p1+tuxcare of enshrined/svg-sanitize.",
      "vulnerability": {
        "name": "CVE-2025-55166"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-kernel@v7.4.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-kernel@v7.4.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45075 is fixed in version v7.4.10-p1+tuxcare of symfony/http-kernel.",
      "vulnerability": {
        "name": "CVE-2026-45075"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      },
      "action_statement": "Vulnerability CVE-2022-29248 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      },
      "action_statement": "Vulnerability CVE-2022-31043 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      },
      "action_statement": "Vulnerability CVE-2022-31090 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      },
      "action_statement": "Vulnerability CVE-2022-31091 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      },
      "action_statement": "Vulnerability CVE-2026-55568 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      },
      "action_statement": "Vulnerability CVE-2026-55767 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/form_builder@7.1.22-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/form_builder@7.1.22-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0749 is fixed in version 7.1.22-p1+tuxcare of drupal/form_builder.",
      "vulnerability": {
        "name": "CVE-2026-0749"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54370 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2025-54370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34084 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-34084"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35453 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-35453"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40296 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-40296"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40863 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-40863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40902 is fixed in version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-40902"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59931 does not affect version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet. not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59931"
      },
      "impact_statement": "not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59932 affects version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59932"
      },
      "action_statement": "Vulnerability CVE-2026-59932 affects version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59933 affects version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59933"
      },
      "action_statement": "Vulnerability CVE-2026-59933 affects version 4.5.0-p2+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45065 is fixed in version v6.4.37-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-45065"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v6.4.37-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48784 is fixed in version v6.4.37-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-48784"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3838 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3902 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-0085 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-0085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2400 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-2400"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28368 does not affect version 1.2.2-p2+tuxcare of dompdf/dompdf. already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-28368"
      },
      "impact_statement": "already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41343 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-41343"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23924 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-23924"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50262 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-50262"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55554 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-55554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55555 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-55555"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56722 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-56722"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59941 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59942 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59942"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59943 is fixed in version 1.2.2-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59943"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p1+tuxcare of illuminate/database.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/database@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg affects version 5.4.36-p1+tuxcare of illuminate/database, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      },
      "action_statement": "Vulnerability GHSA-x7p5-p2c9-phvg affects version 5.4.36-p1+tuxcare of illuminate/database, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/spamspan@3.2.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/spamspan@3.2.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31687 is fixed in version 3.2.0-p1+tuxcare of drupal/spamspan.",
      "vulnerability": {
        "name": "CVE-2025-31687"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7809 does not affect version v2.16.1-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is Twig version 2.16.1, which contains the fix introduced in 1.20.0. The vulnerability allowed remote code execution via the _self variable in templates when Sandbox mode was enabled. The fix adds a type validation check in the displayBlock function that ensures template blocks must be instances of \\Twig\\Template, preventin...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2015-7809"
      },
      "impact_statement": "already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is Twig version 2.16.1, which contains the fix introduced in 1.20.0. The vulnerability allowed remote code execution via the _self variable in templates when Sandbox mode was enabled. The fix adds a type validation check in the displayBlock function that ensures template blocks must be instances of \\Twig\\Template, preventin..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-9942 does not affect version v2.16.1-p2+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 has been fixed in Twig 2.16.1. The target contains the complete mitigation introduced in Twig 2.7.0 that prevents __toString() method calls from bypassing sandbox security policy restrictions.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2019-9942"
      },
      "impact_statement": "already_fixed \u2014 CVE-2019-9942 has been fixed in Twig 2.16.1. The target contains the complete mitigation introduced in Twig 2.7.0 that prevents __toString() method calls from bypassing sandbox security policy restrictions."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51754 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51755 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51755"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24425 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-24425"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46628 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46633 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46633"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46635 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46638 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47732 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-47732"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48805 does not affect version v2.16.1-p2+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48805 describes a sandbox bypass in Twig v3.26.0 where deprecated wrapper functions in src/Resources/core.php fail to forward sandbox state to refactored CoreExtension class methods. Target v2.16.1 uses a completely different architecture where the vulnerable delegation pattern does not exist. The functions twig_array_some() and twig_array_every() don't exist in v2.16.1, and twig_check...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48805"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-48805 describes a sandbox bypass in Twig v3.26.0 where deprecated wrapper functions in src/Resources/core.php fail to forward sandbox state to refactored CoreExtension class methods. Target v2.16.1 uses a completely different architecture where the vulnerable delegation pattern does not exist. The functions twig_array_some() and twig_array_every() don't exist in v2.16.1, and twig_check..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48806 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48806"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48807 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48807"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48808 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49981 is fixed in version v2.16.1-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-49981"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@11.4.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@11.4.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 11.4.4-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 6.20.45-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 does not affect version 6.20.45-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 6.20.45-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 6.20.45-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/filefield_paths@7.1.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/filefield_paths@7.1.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1556 is fixed in version 7.1.2-p1+tuxcare of drupal/filefield_paths.",
      "vulnerability": {
        "name": "CVE-2026-1556"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10963 does not affect version 6.11.1-p1+tuxcare of firebase/php-jwt. already_fixed \u2014 The target repository firebase/php-jwt version 6.11.1 has already been fixed for AIKIDO-2025-10963 (Inadequate Encryption Strength). TuxCare applied an identical backport in commit 9d756cb (PHPELSCVE-211) that implements the same key length validation as the upstream patch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "AIKIDO-2025-10963"
      },
      "impact_statement": "already_fixed \u2014 The target repository firebase/php-jwt version 6.11.1 has already been fixed for AIKIDO-2025-10963 (Inadequate Encryption Strength). TuxCare applied an identical backport in commit 9d756cb (PHPELSCVE-211) that implements the same key length validation as the upstream patch."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/firebase/php-jwt@6.11.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45769 affects version 6.11.1-p1+tuxcare of firebase/php-jwt, and is fixed in 6.11.1-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-45769"
      },
      "action_statement": "Vulnerability CVE-2025-45769 affects version 6.11.1-p1+tuxcare of firebase/php-jwt, and is fixed in 6.11.1-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/nesbot/carbon@1.26.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/nesbot/carbon@1.26.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22145 is fixed in version 1.26.6-p1+tuxcare of nesbot/carbon.",
      "vulnerability": {
        "name": "CVE-2025-22145"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.11.0-p4+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/gdpr@7.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/gdpr@7.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31689 is fixed in version 7.1.0-p1+tuxcare of drupal/gdpr.",
      "vulnerability": {
        "name": "CVE-2025-31689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "action_statement": "Vulnerability CVE-2025-57811 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      },
      "action_statement": "Vulnerability CVE-2025-68437 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "action_statement": "Vulnerability CVE-2026-25494 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "action_statement": "Vulnerability CVE-2026-25496 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "action_statement": "Vulnerability CVE-2026-25498 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      },
      "action_statement": "Vulnerability CVE-2026-27127 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "action_statement": "Vulnerability CVE-2026-27129 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      },
      "action_statement": "Vulnerability CVE-2026-28783 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      },
      "action_statement": "Vulnerability CVE-2026-29069 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "action_statement": "Vulnerability CVE-2026-29113 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "action_statement": "Vulnerability CVE-2026-31859 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "action_statement": "Vulnerability CVE-2026-32267 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "action_statement": "Vulnerability CVE-2026-33158 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "action_statement": "Vulnerability CVE-2026-33159 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "action_statement": "Vulnerability CVE-2026-33160 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "action_statement": "Vulnerability CVE-2026-33161 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      },
      "action_statement": "Vulnerability CVE-2026-55790 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "action_statement": "Vulnerability CVE-2026-56383 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      },
      "action_statement": "Vulnerability CVE-2026-56384 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "action_statement": "Vulnerability CVE-2026-56385 affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      },
      "action_statement": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      },
      "action_statement": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      },
      "action_statement": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p1+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p1+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p1+tuxcare of craftcms/cms."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      },
      "action_statement": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p1+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3838 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3902 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-0085 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-0085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2400 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-2400"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28368 does not affect version 1.2.2-p1+tuxcare of dompdf/dompdf. already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-28368"
      },
      "impact_statement": "already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41343 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-41343"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23924 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-23924"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50262 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-50262"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55554 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55554"
      },
      "action_statement": "Vulnerability CVE-2026-55554 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55555 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55555"
      },
      "action_statement": "Vulnerability CVE-2026-55555 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56722 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56722"
      },
      "action_statement": "Vulnerability CVE-2026-56722 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59941 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59941"
      },
      "action_statement": "Vulnerability CVE-2026-59941 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59942 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59942"
      },
      "action_statement": "Vulnerability CVE-2026-59942 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59943 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59943"
      },
      "action_statement": "Vulnerability CVE-2026-59943 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 does not affect version 5.5.50-p2+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2018-15133"
      },
      "impact_statement": "Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43617"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.5.50-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.5.50-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6jvx-8ch9-j2jr does not affect version 5.5.50-p2+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6jvx-8ch9-j2jr"
      },
      "impact_statement": "Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.5.50-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.5.50-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@4.8.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@4.8.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 4.8.10-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54370 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2025-54370"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34084 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-34084"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35453 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-35453"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40296 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-40296"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40863 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-40863"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40902 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-40902"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59931 does not affect version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet. not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59931"
      },
      "impact_statement": "not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59932 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-59932"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59933 is fixed in version 4.5.0-p3+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2026-59933"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 7.30.7-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 7.30.7-p2+tuxcare of laravel/framework, and is fixed in 7.30.7-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 7.30.7-p2+tuxcare of laravel/framework, and is fixed in 7.30.7-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-50345 is fixed in version 4.4.49-p2+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2024-50345"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@4.4.49-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64500 is fixed in version 4.4.49-p2+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2025-64500"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 7.30.7-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 7.30.7-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 7.10.0-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 7.10.0-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 7.10.0-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 7.10.0-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2021-20332 is a false positive for mongodb/mongodb 1.9.0-p1+tuxcare. false_positive \u2014 CVE-2021-20332 concerns the MongoDB Rust Driver, but the target repository is the MongoDB PHP Library (mongodb/mongodb) version 1.9.0. This is a wrong-project match - the CVE applies to a different product in a different programming language.",
      "vulnerability": {
        "name": "CVE-2021-20332"
      },
      "impact_statement": "false_positive \u2014 CVE-2021-20332 concerns the MongoDB Rust Driver, but the target repository is the MongoDB PHP Library (mongodb/mongodb) version 1.9.0. This is a wrong-project match - the CVE applies to a different product in a different programming language."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2021-32050 affects version 1.9.0-p1+tuxcare of mongodb/mongodb and will not be fixed. Security fix is in mongo-c-driver (a C library we don't maintain). PHP picks it up indirectly through the PECL ext-mongodb extension, which ships a new binary bundling the patched libmongoc. mongo-php-library itself receives no source-code change \u2014 a future release may bump its ext-mongodb version requirement, but no direct patch applies here.",
      "vulnerability": {
        "name": "CVE-2021-32050"
      },
      "action_statement": "Vulnerability CVE-2021-32050 affects version 1.9.0-p1+tuxcare of mongodb/mongodb and will not be fixed. Security fix is in mongo-c-driver (a C library we don't maintain). PHP picks it up indirectly through the PECL ext-mongodb extension, which ships a new binary bundling the patched libmongoc. mongo-php-library itself receives no source-code change \u2014 a future release may bump its ext-mongodb version requirement, but no direct patch applies here."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-11695 is a false positive for mongodb/mongodb 1.9.0-p1+tuxcare. false_positive \u2014 CVE-2025-11695 affects the MongoDB Rust Driver, but this repository is the MongoDB PHP Library. These are separate codebases for different language ecosystems with no code sharing, vendoring, or dependency relationship. The CVE's tlsInsecure parameter logic does not exist in this PHP library.",
      "vulnerability": {
        "name": "CVE-2025-11695"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-11695 affects the MongoDB Rust Driver, but this repository is the MongoDB PHP Library. These are separate codebases for different language ecosystems with no code sharing, vendoring, or dependency relationship. The CVE's tlsInsecure parameter logic does not exist in this PHP library."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/mongodb/mongodb@1.9.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2026-81525 is fixed in version 1.9.0-p1+tuxcare of mongodb/mongodb.",
      "vulnerability": {
        "name": "CVE-2026-81525"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p7+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p7+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products.",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab...",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th...",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p7+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron...",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n...",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t...",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core...",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra...",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil...",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p7+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do...",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p7+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-51651 is fixed in version 3.263.4-p1+tuxcare of aws/aws-sdk-php.",
      "vulnerability": {
        "name": "CVE-2023-51651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14761 affects version 3.263.4-p1+tuxcare of aws/aws-sdk-php, and is fixed in 3.263.4-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14761"
      },
      "action_statement": "Vulnerability CVE-2025-14761 affects version 3.263.4-p1+tuxcare of aws/aws-sdk-php, and is fixed in 3.263.4-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-27qh-8cxx-2cr5 affects version 3.263.4-p1+tuxcare of aws/aws-sdk-php, and is fixed in 3.263.4-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-27qh-8cxx-2cr5"
      },
      "action_statement": "Vulnerability GHSA-27qh-8cxx-2cr5 affects version 3.263.4-p1+tuxcare of aws/aws-sdk-php, and is fixed in 3.263.4-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/tfa_basic@7.1.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/tfa_basic@7.1.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6816 is fixed in version 7.1.2-p1+tuxcare of drupal/tfa_basic.",
      "vulnerability": {
        "name": "CVE-2026-6816"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/protected_pages@7.2.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/protected_pages@7.2.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-9551 is fixed in version 7.2.4-p1+tuxcare of drupal/protected_pages.",
      "vulnerability": {
        "name": "CVE-2025-9551"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 is fixed in version v4.4.45-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 is fixed in version v4.4.45-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v4.4.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v4.4.45-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 7.30.7-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 7.30.7-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p5+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24775 is fixed in version 1.1.0-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2022-24775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29197 is fixed in version 1.1.0-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2023-29197"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48998 is fixed in version 1.1.0-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-48998"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49214 is fixed in version 1.1.0-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-49214"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55766 is fixed in version 1.1.0-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-55766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59882 is fixed in version 1.1.0-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-59882"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 9.52.21-p1+tuxcare of laravel/framework, and is fixed in 9.52.21-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 9.52.21-p1+tuxcare of laravel/framework, and is fixed in 9.52.21-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 9.52.21-p1+tuxcare of laravel/framework, and is fixed in 9.52.21-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 9.52.21-p1+tuxcare of laravel/framework, and is fixed in 9.52.21-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      },
      "action_statement": "Vulnerability CVE-2014-2681 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      },
      "action_statement": "Vulnerability CVE-2014-2682 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      },
      "action_statement": "Vulnerability CVE-2014-2683 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      },
      "action_statement": "Vulnerability GHSA-6fqw-j3vm-7f66 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      },
      "action_statement": "Vulnerability GHSA-848f-mph5-9pm9 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      },
      "action_statement": "Vulnerability GHSA-8xhv-gqm4-3w99 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g is fixed in version 1.12.10-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      },
      "action_statement": "Vulnerability GHSA-v42g-7q2x-cw32 affects version 1.12.10-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.12.10-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 10.48.28-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.48.28-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.28-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.48.28-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.48.28 does not contain the vulnerable code path. The vulnerability (GHSA-crmm-hgp2-wgrp) affects Laravel 11+'s LocalFilesystemAdapter class, which was introduced in Laravel 11 and does not exist in Laravel 10. Laravel 10 uses a delegating architecture where FilesystemAdapter throws RuntimeException for local filesystem temporary URLs rather than implementing them.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.48.28 does not contain the vulnerable code path. The vulnerability (GHSA-crmm-hgp2-wgrp) affects Laravel 11+'s LocalFilesystemAdapter class, which was introduced in Laravel 11 and does not exist in Laravel 10. Laravel 10 uses a delegating architecture where FilesystemAdapter throws RuntimeException for local filesystem temporary URLs rather than implementing them."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40476 is fixed in version v14.11.10-p1+tuxcare of webonyx/graphql-php.",
      "vulnerability": {
        "name": "CVE-2026-40476"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-68jq-c3rv-pcrr is fixed in version v14.11.10-p1+tuxcare of webonyx/graphql-php.",
      "vulnerability": {
        "name": "GHSA-68jq-c3rv-pcrr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-fc86-6rv6-2jpm is fixed in version v14.11.10-p1+tuxcare of webonyx/graphql-php.",
      "vulnerability": {
        "name": "GHSA-fc86-6rv6-2jpm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/webonyx/graphql-php@v14.11.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-r7cg-qjjm-xhqq is fixed in version v14.11.10-p1+tuxcare of webonyx/graphql-php.",
      "vulnerability": {
        "name": "GHSA-r7cg-qjjm-xhqq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.3-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.3-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.3-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 affects version 8.83.29-p1+tuxcare of laravel/framework, and is fixed in 8.83.29-p2+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      },
      "action_statement": "Vulnerability AIKIDO-2026-10659 affects version 8.83.29-p1+tuxcare of laravel/framework, and is fixed in 8.83.29-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.83.29-p1+tuxcare of laravel/framework, and is fixed in 8.83.29-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.83.29-p1+tuxcare of laravel/framework, and is fixed in 8.83.29-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/flag@7.3.9-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/flag@7.3.9-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14556 is fixed in version 7.3.9-p1+tuxcare of drupal/flag.",
      "vulnerability": {
        "name": "CVE-2025-14556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@5.4.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@5.4.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51736 is fixed in version 5.4.45-p2+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2024-51736"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@5.4.45-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@5.4.45-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24739 is fixed in version 5.4.45-p2+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2026-24739"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45065 is fixed in version v4.4.44-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-45065"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v4.4.44-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48784 is fixed in version v4.4.44-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-48784"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@4.4.44-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@4.4.44-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51736 is fixed in version 4.4.44-p1+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2024-51736"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@4.4.44-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@4.4.44-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24739 is fixed in version 4.4.44-p1+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2026-24739"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10963 does not affect version 6.11.1-p2+tuxcare of firebase/php-jwt. already_fixed \u2014 The target repository firebase/php-jwt version 6.11.1 has already been fixed for AIKIDO-2025-10963 (Inadequate Encryption Strength). TuxCare applied an identical backport in commit 9d756cb (PHPELSCVE-211) that implements the same key length validation as the upstream patch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "AIKIDO-2025-10963"
      },
      "impact_statement": "already_fixed \u2014 The target repository firebase/php-jwt version 6.11.1 has already been fixed for AIKIDO-2025-10963 (Inadequate Encryption Strength). TuxCare applied an identical backport in commit 9d756cb (PHPELSCVE-211) that implements the same key length validation as the upstream patch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/firebase/php-jwt@6.11.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45769 is fixed in version 6.11.1-p2+tuxcare of firebase/php-jwt.",
      "vulnerability": {
        "name": "CVE-2025-45769"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.7.29-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.7.29-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.7.29-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.7.29 uses SwiftMailer, not Symfony Mailer. The GHSA-5vg9-5847-vvmq vulnerability specifically requires Symfony Mailer's handling of CRLF sequences. SwiftMailer employs EmailValidator which rejects CRLF in email addresses, breaking the attack chain.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.7.29 uses SwiftMailer, not Symfony Mailer. The GHSA-5vg9-5847-vvmq vulnerability specifically requires Symfony Mailer's handling of CRLF sequences. SwiftMailer employs EmailValidator which rejects CRLF in email addresses, breaking the attack chain."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.7.29-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.7.29 does not support temporary signed URLs for local filesystem storage. The vulnerable feature (LocalFilesystemAdapter with temporaryUrl/temporaryUploadUrl methods) does not exist in this version. The FilesystemAdapter::temporaryUrl() method explicitly throws RuntimeException when used with LocalAdapter.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.7.29 does not support temporary signed URLs for local filesystem storage. The vulnerable feature (LocalFilesystemAdapter with temporaryUrl/temporaryUploadUrl methods) does not exist in this version. The FilesystemAdapter::temporaryUrl() method explicitly throws RuntimeException when used with LocalAdapter."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.7.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51754 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51754"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51755 affects version v1.44.8-p1+tuxcare of twig/twig, and is fixed in v1.44.8-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-51755"
      },
      "action_statement": "Vulnerability CVE-2024-51755 affects version v1.44.8-p1+tuxcare of twig/twig, and is fixed in v1.44.8-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46628 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46633 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46633"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46635 does not affect version v1.44.8-p1+tuxcare of twig/twig. not_affected \u2014 The `column` filter that is the subject of CVE-2026-46635 does not exist in Twig 1.44.8. This version is part of the Twig 1.x series (CHANGELOG notes v1.44.6 as \"Last version for the 1.x series\"), while the column filter was introduced in Twig 2.x. Without this filter, the vulnerable code path (template calls column filter \u2192 delegates to array_column() \u2192 reads object properties bypassing sandbo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-46635"
      },
      "impact_statement": "not_affected \u2014 The `column` filter that is the subject of CVE-2026-46635 does not exist in Twig 1.44.8. This version is part of the Twig 1.x series (CHANGELOG notes v1.44.6 as \"Last version for the 1.x series\"), while the column filter was introduced in Twig 2.x. Without this filter, the vulnerable code path (template calls column filter \u2192 delegates to array_column() \u2192 reads object properties bypassing sandbo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46638 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47732 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-47732"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48805 does not affect version v1.44.8-p1+tuxcare of twig/twig. not_affected \u2014 Target Twig 1.44.8 is NOT AFFECTED by CVE-2026-48805. This vulnerability is specific to Twig 3.26.0+ architectural changes that introduced per-source sandbox state with boolean parameters. The three vulnerable deprecated wrapper functions mentioned in the CVE (twig_array_some(), twig_array_every(), twig_check_arrow_in_sandbox()) do not exist in Twig 1.44.x. The equivalent functionality in Twig ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48805"
      },
      "impact_statement": "not_affected \u2014 Target Twig 1.44.8 is NOT AFFECTED by CVE-2026-48805. This vulnerability is specific to Twig 3.26.0+ architectural changes that introduced per-source sandbox state with boolean parameters. The three vulnerable deprecated wrapper functions mentioned in the CVE (twig_array_some(), twig_array_every(), twig_check_arrow_in_sandbox()) do not exist in Twig 1.44.x. The equivalent functionality in Twig ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48806 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48806"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48807 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48807"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48808 does not affect version v1.44.8-p1+tuxcare of twig/twig. not_affected \u2014 Twig v1.44.8 is not affected by CVE-2026-48808. The vulnerability concerns a sandbox bypass in the `column` filter when sandboxing is enabled via `SourcePolicyInterface`. However, v1.44.8 lacks both the column filter feature (introduced in later Twig versions 2.x/3.x) and the SourcePolicyInterface mechanism. Exhaustive searches across the codebase confirmed no column filter registration in Core...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48808"
      },
      "impact_statement": "not_affected \u2014 Twig v1.44.8 is not affected by CVE-2026-48808. The vulnerability concerns a sandbox bypass in the `column` filter when sandboxing is enabled via `SourcePolicyInterface`. However, v1.44.8 lacks both the column filter feature (introduced in later Twig versions 2.x/3.x) and the SourcePolicyInterface mechanism. Exhaustive searches across the codebase confirmed no column filter registration in Core..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49981 is fixed in version v1.44.8-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-49981"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 12.58.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 12.58.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 12.58.0-p2+tuxcare of laravel/framework, and is fixed in 12.58.0-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "action_statement": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 12.58.0-p2+tuxcare of laravel/framework, and is fixed in 12.58.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-45440"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      },
      "action_statement": "Vulnerability CVE-2025-13080 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      },
      "action_statement": "Vulnerability CVE-2025-13081 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      },
      "action_statement": "Vulnerability CVE-2025-13082 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      },
      "action_statement": "Vulnerability CVE-2025-13083 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      },
      "action_statement": "Vulnerability CVE-2026-6366 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      },
      "action_statement": "Vulnerability CVE-2026-9082 affects version 9.5.11-p2+tuxcare of drupal/core, and is fixed in 9.5.11-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6CCV-8FGF-CJPW"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p2+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      },
      "impact_statement": "already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-form@2.1.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-form@2.1.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gvpp-6jrj-5pqc is fixed in version 2.1.6-p1+tuxcare of zendframework/zend-form.",
      "vulnerability": {
        "name": "GHSA-gvpp-6jrj-5pqc"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 11.51.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 11.51.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.51.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp is fixed in version 11.51.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45065 is fixed in version v7.4.9-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-45065"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v7.4.9-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48784 is fixed in version v7.4.9-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-48784"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-session@2.1.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-session@2.1.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-96c6-m98x-hxjx is fixed in version 2.1.6-p2+tuxcare of zendframework/zend-session.",
      "vulnerability": {
        "name": "GHSA-96c6-m98x-hxjx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.3-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.3-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.3-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 affects version v2.8.52-p2+tuxcare of symfony/yaml, and is fixed in v2.8.52-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      },
      "action_statement": "Vulnerability CVE-2026-45133 affects version v2.8.52-p2+tuxcare of symfony/yaml, and is fixed in v2.8.52-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 is fixed in version v2.8.52-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v2.8.52-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p6+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p6+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p6+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p6+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-45440"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p6+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6CCV-8FGF-CJPW"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p6+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      },
      "impact_statement": "already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phenx/php-svg-lib@0.4.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phenx/php-svg-lib@0.4.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50251 is fixed in version 0.4.1-p1+tuxcare of phenx/php-svg-lib.",
      "vulnerability": {
        "name": "CVE-2023-50251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phenx/php-svg-lib@0.4.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phenx/php-svg-lib@0.4.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-25117 is fixed in version 0.4.1-p1+tuxcare of phenx/php-svg-lib.",
      "vulnerability": {
        "name": "CVE-2024-25117"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phenx/php-svg-lib@0.4.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phenx/php-svg-lib@0.4.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-97m3-52wr-xvv2 is fixed in version 0.4.1-p1+tuxcare of phenx/php-svg-lib.",
      "vulnerability": {
        "name": "GHSA-97m3-52wr-xvv2"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-45440"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 affects version 9.5.11-p4+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      },
      "action_statement": "Vulnerability CVE-2025-13081 affects version 9.5.11-p4+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 affects version 9.5.11-p4+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      },
      "action_statement": "Vulnerability CVE-2025-13082 affects version 9.5.11-p4+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 affects version 9.5.11-p4+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      },
      "action_statement": "Vulnerability CVE-2025-13083 affects version 9.5.11-p4+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p4+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6CCV-8FGF-CJPW"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p4+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      },
      "impact_statement": "already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 affects version v2.8.52-p1+tuxcare of symfony/yaml, and is fixed in v2.8.52-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      },
      "action_statement": "Vulnerability CVE-2026-45133 affects version v2.8.52-p1+tuxcare of symfony/yaml, and is fixed in v2.8.52-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 affects version v2.8.52-p1+tuxcare of symfony/yaml, and is fixed in v2.8.52-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      },
      "action_statement": "Vulnerability CVE-2026-45304 affects version v2.8.52-p1+tuxcare of symfony/yaml, and is fixed in v2.8.52-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v2.8.52-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v2.8.52-p1+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p3+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p3+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products.",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab...",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th...",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p3+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron...",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n...",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t...",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core...",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra...",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil...",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p3+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do...",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p3+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      },
      "action_statement": "Vulnerability CVE-2011-1939 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      },
      "action_statement": "Vulnerability CVE-2012-4451 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      },
      "action_statement": "Vulnerability CVE-2015-3154 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      },
      "action_statement": "Vulnerability CVE-2015-5723 affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      },
      "action_statement": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      },
      "action_statement": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.10.6-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.10.6-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@5.7.27-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@5.7.27-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 does not affect version 5.7.27-p1+tuxcare of phpunit/phpunit. PHPUnit version 5.7.27 does not contain the vulnerable code path. The PHPT code coverage feature, including the cleanupForCoverage() method that performs unsafe deserialization of .coverage files, was introduced in later versions (between 5.7.x and 6.5.x). This version lacks all code coverage functionality for PHPT tests and never processes .coverage files, making the deserialization vulnerability impossible to trigger.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-24765"
      },
      "impact_statement": "PHPUnit version 5.7.27 does not contain the vulnerable code path. The PHPT code coverage feature, including the cleanupForCoverage() method that performs unsafe deserialization of .coverage files, was introduced in later versions (between 5.7.x and 6.5.x). This version lacks all code coverage functionality for PHPT tests and never processes .coverage files, making the deserialization vulnerability impossible to trigger."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-kernel@v3.4.49-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-kernel@v3.4.49-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24894 is fixed in version v3.4.49-p1+tuxcare of symfony/http-kernel.",
      "vulnerability": {
        "name": "CVE-2022-24894"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "action_statement": "Vulnerability CVE-2025-57811 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "action_statement": "Vulnerability CVE-2026-25494 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "action_statement": "Vulnerability CVE-2026-25498 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "action_statement": "Vulnerability CVE-2026-27129 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "action_statement": "Vulnerability CVE-2026-29113 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "action_statement": "Vulnerability CVE-2026-31859 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "action_statement": "Vulnerability CVE-2026-33158 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "action_statement": "Vulnerability CVE-2026-33159 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "action_statement": "Vulnerability CVE-2026-33160 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "action_statement": "Vulnerability CVE-2026-33161 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      },
      "action_statement": "Vulnerability CVE-2026-55790 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "action_statement": "Vulnerability CVE-2026-56383 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      },
      "action_statement": "Vulnerability CVE-2026-56384 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "action_statement": "Vulnerability CVE-2026-56385 affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      },
      "action_statement": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      },
      "action_statement": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p5+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p5+tuxcare of craftcms/cms."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      },
      "action_statement": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p5+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3838 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3902 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-0085 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-0085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2400 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-2400"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28368 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-28368"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41343 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-41343"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23924 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-23924"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50262 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-50262"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55554 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-55554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55555 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-55555"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56722 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-56722"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59941 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59942 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59942"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59943 is fixed in version 0.8.6-p2+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59943"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f8fg-pg57-v4j8 is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-f8fg-pg57-v4j8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mh25-x5hq-wrqp is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mh25-x5hq-wrqp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mj63-m3rc-8ppr is fixed in version 2.7.1-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mj63-m3rc-8ppr"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p4+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p4+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products.",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab...",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th...",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p4+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron...",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n...",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t...",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core...",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra...",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil...",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p4+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do...",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p4+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 affects version 5.8.38-p2+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      },
      "action_statement": "Vulnerability CVE-2024-52301 affects version 5.8.38-p2+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 5.8.38-p2+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 5.8.38-p2+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p2+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p2+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 affects version 5.8.38-p3+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      },
      "action_statement": "Vulnerability CVE-2024-52301 affects version 5.8.38-p3+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 5.8.38-p3+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 5.8.38-p3+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p3+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p3+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/monolog/monolog@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/monolog/monolog@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f57v-q966-7fh6 is fixed in version 1.11.0-p1+tuxcare of monolog/monolog.",
      "vulnerability": {
        "name": "GHSA-f57v-q966-7fh6"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p5+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p5+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products.",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab...",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th...",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p5+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron...",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n...",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t...",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core...",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra...",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil...",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p5+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do...",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p5+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p2+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45065 is fixed in version v5.4.48-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-45065"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v5.4.48-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48784 is fixed in version v5.4.48-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-48784"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/doctrine/orm@2.8.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/doctrine/orm@2.8.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-vjrg-wpm8-rhrw is fixed in version 2.8.3-p1+tuxcare of doctrine/orm.",
      "vulnerability": {
        "name": "GHSA-vjrg-wpm8-rhrw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p4+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p4+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p1+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.1-p1+tuxcare of laravel/framework, and is fixed in 8.12.1-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.12.1-p1+tuxcare of laravel/framework, and is fixed in 8.12.1-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.7.29-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.7.29-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.7.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.7.29 uses SwiftMailer, not Symfony Mailer. The GHSA-5vg9-5847-vvmq vulnerability specifically requires Symfony Mailer's handling of CRLF sequences. SwiftMailer employs EmailValidator which rejects CRLF in email addresses, breaking the attack chain.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.7.29 uses SwiftMailer, not Symfony Mailer. The GHSA-5vg9-5847-vvmq vulnerability specifically requires Symfony Mailer's handling of CRLF sequences. SwiftMailer employs EmailValidator which rejects CRLF in email addresses, breaking the attack chain."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.7.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.7.29 does not support temporary signed URLs for local filesystem storage. The vulnerable feature (LocalFilesystemAdapter with temporaryUrl/temporaryUploadUrl methods) does not exist in this version. The FilesystemAdapter::temporaryUrl() method explicitly throws RuntimeException when used with LocalAdapter.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.7.29 does not support temporary signed URLs for local filesystem storage. The vulnerable feature (LocalFilesystemAdapter with temporaryUrl/temporaryUploadUrl methods) does not exist in this version. The FilesystemAdapter::temporaryUrl() method explicitly throws RuntimeException when used with LocalAdapter."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.7.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.7.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3007 is fixed in version 2.5.6-p1+tuxcare of zendframework/zend-http.",
      "vulnerability": {
        "name": "CVE-2021-3007"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-cg8w-5jrc-675g affects version 2.5.6-p1+tuxcare of zendframework/zend-http, and is fixed in 2.5.6-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-cg8w-5jrc-675g"
      },
      "action_statement": "Vulnerability GHSA-cg8w-5jrc-675g affects version 2.5.6-p1+tuxcare of zendframework/zend-http, and is fixed in 2.5.6-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-http@2.5.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f6p5-76fp-m248 does not affect version 2.5.6-p1+tuxcare of zendframework/zend-http. already_fixed \u2014 The target repository has already been patched. The vulnerability (GHSA-f6p5-76fp-m248 / ZF2018-01) was fixed in commit 80b11a4c9a711ec50bca8892af91f809a2d1b958 ('Backport GHSA-cg8w-5jrc-675g to 2.5.6') dated 2026-06-24, which removed the code that unconditionally reads X-Rewrite-Url and X-Original-Url headers. The fix is identical to the upstream patch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-f6p5-76fp-m248"
      },
      "impact_statement": "already_fixed \u2014 The target repository has already been patched. The vulnerability (GHSA-f6p5-76fp-m248 / ZF2018-01) was fixed in commit 80b11a4c9a711ec50bca8892af91f809a2d1b958 ('Backport GHSA-cg8w-5jrc-675g to 2.5.6') dated 2026-06-24, which removed the code that unconditionally reads X-Rewrite-Url and X-Original-Url headers. The fix is identical to the upstream patch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3838 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3902 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-0085 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-0085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2400 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-2400"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28368 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-28368"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41343 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-41343"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23924 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-23924"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50262 is fixed in version 0.8.6-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-50262"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55554 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55554"
      },
      "action_statement": "Vulnerability CVE-2026-55554 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55555 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55555"
      },
      "action_statement": "Vulnerability CVE-2026-55555 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56722 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56722"
      },
      "action_statement": "Vulnerability CVE-2026-56722 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59941 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59941"
      },
      "action_statement": "Vulnerability CVE-2026-59941 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59942 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59942"
      },
      "action_statement": "Vulnerability CVE-2026-59942 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@0.8.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59943 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59943"
      },
      "action_statement": "Vulnerability CVE-2026-59943 affects version 0.8.6-p1+tuxcare of dompdf/dompdf, and is fixed in 0.8.6-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.0.2-p4+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.0.2-p4+tuxcare of guzzlehttp/guzzle, and is fixed in 6.0.2-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45067 is fixed in version v7.4.9-p1+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45067"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v7.4.9-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45070 is fixed in version v7.4.9-p1+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45070"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46734 is fixed in version 1.6.7-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2025-46734"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      },
      "action_statement": "Vulnerability CVE-2026-30838 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p2+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      },
      "action_statement": "Vulnerability CVE-2026-71478 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      },
      "action_statement": "Vulnerability CVE-2026-71488 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-c2pc-g5qf-rfrf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      },
      "action_statement": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      },
      "action_statement": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p2+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24775 is fixed in version 1.1.0-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2022-24775"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29197 affects version 1.1.0-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.1.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2023-29197"
      },
      "action_statement": "Vulnerability CVE-2023-29197 affects version 1.1.0-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.1.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48998 is fixed in version 1.1.0-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-48998"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49214 is fixed in version 1.1.0-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-49214"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55766 is fixed in version 1.1.0-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-55766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59882 is fixed in version 1.1.0-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-59882"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-14775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-16894"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2018-15133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p5+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p5+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p5+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch...",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-7852-w36x-6mf6"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p5+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-50345 affects version 4.4.49-p1+tuxcare of symfony/http-foundation, and is fixed in 4.4.49-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-50345"
      },
      "action_statement": "Vulnerability CVE-2024-50345 affects version 4.4.49-p1+tuxcare of symfony/http-foundation, and is fixed in 4.4.49-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@4.4.49-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64500 is fixed in version 4.4.49-p1+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2025-64500"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-10074 does not affect version 6.0.2-p1+tuxcare of swiftmailer/swiftmailer. already_fixed \u2014 The target repository (swiftmailer v6.0.2) is NOT vulnerable to CVE-2016-10074. The vulnerable Swift_Transport_MailTransport class was completely removed from the codebase in version 6.0.0, prior to the current version. The security fix was first applied in version 5.4.5 (December 2016), the mail transport was deprecated, and then the entire class was removed in version 6.0.0 (May 2017). The cu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2016-10074"
      },
      "impact_statement": "already_fixed \u2014 The target repository (swiftmailer v6.0.2) is NOT vulnerable to CVE-2016-10074. The vulnerable Swift_Transport_MailTransport class was completely removed from the codebase in version 6.0.0, prior to the current version. The security fix was first applied in version 5.4.5 (December 2016), the mail transport was deprecated, and then the entire class was removed in version 6.0.0 (May 2017). The cu..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/swiftmailer/swiftmailer@6.0.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28859 is fixed in version 6.0.2-p1+tuxcare of swiftmailer/swiftmailer.",
      "vulnerability": {
        "name": "CVE-2024-28859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/gdpr@3.0.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/gdpr@3.0.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2025-31689 is fixed in version 3.0.0-p1+tuxcare of drupal/gdpr.",
      "vulnerability": {
        "name": "CVE-2025-31689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 9.52.21-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 9.52.21-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45067 is fixed in version v5.4.45-p1+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45067"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v5.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45070 is fixed in version v5.4.45-p1+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45070"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 6.3.3-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 affects version v3.4.47-p1+tuxcare of symfony/yaml, and is fixed in v3.4.47-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      },
      "action_statement": "Vulnerability CVE-2026-45133 affects version v3.4.47-p1+tuxcare of symfony/yaml, and is fixed in v3.4.47-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 is fixed in version v3.4.47-p1+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v3.4.47-p1+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/i18n@7.1.35-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/i18n@7.1.35-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0748 is fixed in version 7.1.35-p1+tuxcare of drupal/i18n.",
      "vulnerability": {
        "name": "CVE-2026-0748"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p2+tuxcare of illuminate/database.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/database@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p2+tuxcare of illuminate/database.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p10+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p10+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p10+tuxcare of craftcms/cms."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p10+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@2.8.52-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@2.8.52-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-50345 is fixed in version 2.8.52-p2+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2024-50345"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@2.8.52-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@2.8.52-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64500 is fixed in version 2.8.52-p2+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2025-64500"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-51651 is fixed in version 3.263.4-p3+tuxcare of aws/aws-sdk-php.",
      "vulnerability": {
        "name": "CVE-2023-51651"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14761 is fixed in version 3.263.4-p3+tuxcare of aws/aws-sdk-php.",
      "vulnerability": {
        "name": "CVE-2025-14761"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-27qh-8cxx-2cr5 is fixed in version 3.263.4-p3+tuxcare of aws/aws-sdk-php.",
      "vulnerability": {
        "name": "GHSA-27qh-8cxx-2cr5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-14775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-16894"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2018-15133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      },
      "action_statement": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch...",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-7852-w36x-6mf6"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      },
      "action_statement": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p2+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p8+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p8+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p8+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p8+tuxcare of craftcms/cms."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p8+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p8+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/yiisoft/yii2-dev@2.0.54-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/yiisoft/yii2-dev@2.0.54-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-7269 does not affect version 2.0.54-p1+tuxcare of yiisoft/yii2-dev. CVE-2018-7269 affects Yii 2.x before version 2.0.15 due to SQL injection via unsanitized array input to findOne()/findAll() methods. The target repository is version 2.0.54-p1+tuxcare, which is far beyond the affected range. The vulnerability was fixed by upstream Yii in version 2.0.15 with the introduction of the filterCondition() method that validates array keys against valid column names before constructing SQL queries. This upstream fix is present in version 2.0.54 and was included when the version was snapshot'd for TuxCare ELS maintenance. The vulnerable code pattern is not present because the upstream vendor fixed it.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2018-7269"
      },
      "impact_statement": "CVE-2018-7269 affects Yii 2.x before version 2.0.15 due to SQL injection via unsanitized array input to findOne()/findAll() methods. The target repository is version 2.0.54-p1+tuxcare, which is far beyond the affected range. The vulnerability was fixed by upstream Yii in version 2.0.15 with the introduction of the filterCondition() method that validates array keys against valid column names before constructing SQL queries. This upstream fix is present in version 2.0.54 and was included when the version was snapshot'd for TuxCare ELS maintenance. The vulnerable code pattern is not present because the upstream vendor fixed it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/yiisoft/yii2-dev@2.0.54-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/yiisoft/yii2-dev@2.0.54-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-32877 does not affect version 2.0.54-p1+tuxcare of yiisoft/yii2-dev. not_affected \u2014 Target version 2.0.54 already contains the upstream fix for CVE-2024-32877. The vulnerable code pattern (using ENT_NOQUOTES in htmlEncode) was fixed in upstream Yii 2.0.50 (May 30, 2024) by changing the flag to ENT_QUOTES, which properly encodes quote characters and prevents XSS injection through HTML attributes. The fix is present in ErrorHandler.php line 185.",
      "vulnerability": {
        "name": "CVE-2024-32877"
      },
      "impact_statement": "not_affected \u2014 Target version 2.0.54 already contains the upstream fix for CVE-2024-32877. The vulnerable code pattern (using ENT_NOQUOTES in htmlEncode) was fixed in upstream Yii 2.0.50 (May 30, 2024) by changing the flag to ENT_QUOTES, which properly encodes quote characters and prevents XSS injection through HTML attributes. The fix is present in ErrorHandler.php line 185."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/yiisoft/yii2-dev@2.0.54-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/yiisoft/yii2-dev@2.0.54-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-39850 is fixed in version 2.0.54-p1+tuxcare of yiisoft/yii2-dev.",
      "vulnerability": {
        "name": "CVE-2026-39850"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48998 is fixed in version 1.9.1-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-48998"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49214 is fixed in version 1.9.1-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-49214"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55766 is fixed in version 1.9.1-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-55766"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.9.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59882 affects version 1.9.1-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.9.1-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59882"
      },
      "action_statement": "Vulnerability CVE-2026-59882 affects version 1.9.1-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.9.1-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/yajra/laravel-datatables-oracle@10.11.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/yajra/laravel-datatables-oracle@10.11.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10705 is fixed in version 10.11.4-p1+tuxcare of yajra/laravel-datatables-oracle.",
      "vulnerability": {
        "name": "AIKIDO-2025-10705"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p3+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.12.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.12.10-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "action_statement": "Vulnerability CVE-2025-57811 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "action_statement": "Vulnerability CVE-2026-25494 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "action_statement": "Vulnerability CVE-2026-25496 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "action_statement": "Vulnerability CVE-2026-25498 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "action_statement": "Vulnerability CVE-2026-27129 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "action_statement": "Vulnerability CVE-2026-29113 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "action_statement": "Vulnerability CVE-2026-31859 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "action_statement": "Vulnerability CVE-2026-33158 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "action_statement": "Vulnerability CVE-2026-33159 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "action_statement": "Vulnerability CVE-2026-33160 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "action_statement": "Vulnerability CVE-2026-33161 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      },
      "action_statement": "Vulnerability CVE-2026-55790 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "action_statement": "Vulnerability CVE-2026-56383 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      },
      "action_statement": "Vulnerability CVE-2026-56384 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "action_statement": "Vulnerability CVE-2026-56385 affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      },
      "action_statement": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      },
      "action_statement": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      },
      "action_statement": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p3+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p3+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p3+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p3+tuxcare of craftcms/cms."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      },
      "action_statement": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p3+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 does not affect version 5.5.50-p3+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2018-15133"
      },
      "impact_statement": "Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43617"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.5.50-p3+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.5.50-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6jvx-8ch9-j2jr does not affect version 5.5.50-p3+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6jvx-8ch9-j2jr"
      },
      "impact_statement": "Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.5.50-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.5.50-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/firebase/php-jwt@v5.5.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/firebase/php-jwt@v5.5.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-46743 does not affect version v5.5.1-p1+tuxcare of firebase/php-jwt. not_affected \u2014 The target firebase/php-jwt v5.5.1 is not affected by CVE-2021-46743. The upstream vendor (Google/Firebase) introduced the Key class and algorithm verification defense in v5.5.1 (November 2021), which is the version the target ships. The fix from patch 1 (commit bc0df6440dfe) is present: Key objects bind algorithms to key material, and JWT::decode verifies the JWT's algorithm header matches the...",
      "vulnerability": {
        "name": "CVE-2021-46743"
      },
      "impact_statement": "not_affected \u2014 The target firebase/php-jwt v5.5.1 is not affected by CVE-2021-46743. The upstream vendor (Google/Firebase) introduced the Key class and algorithm verification defense in v5.5.1 (November 2021), which is the version the target ships. The fix from patch 1 (commit bc0df6440dfe) is present: Key objects bind algorithms to key material, and JWT::decode verifies the JWT's algorithm header matches the..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/firebase/php-jwt@v5.5.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/firebase/php-jwt@v5.5.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-45769 is fixed in version v5.5.1-p1+tuxcare of firebase/php-jwt.",
      "vulnerability": {
        "name": "CVE-2025-45769"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55554 is fixed in version 3.1.0-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-55554"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55555 is fixed in version 3.1.0-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-55555"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56722 is fixed in version 3.1.0-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-56722"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59941 is fixed in version 3.1.0-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59942 is fixed in version 3.1.0-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2026-59942"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59943 does not affect version 3.1.0-p1+tuxcare of dompdf/dompdf. not_affected \u2014 Dompdf 3.1.0 is not affected by CVE-2026-59943. The target repository contains comprehensive SVG image reference validation that prevents malicious file:// URIs in SVG <image> elements from reaching the vulnerable code path in the php-svg-lib dependency. The defense mechanism validates all SVG image references against chroot restrictions before passing the SVG to php-svg-lib for rendering, effe...",
      "vulnerability": {
        "name": "CVE-2026-59943"
      },
      "impact_statement": "not_affected \u2014 Dompdf 3.1.0 is not affected by CVE-2026-59943. The target repository contains comprehensive SVG image reference validation that prevents malicious file:// URIs in SVG <image> elements from reaching the vulnerable code path in the php-svg-lib dependency. The defense mechanism validates all SVG image references against chroot restrictions before passing the SVG to php-svg-lib for rendering, effe..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54068 is fixed in version 3.6.3-p1+tuxcare of livewire/livewire.",
      "vulnerability": {
        "name": "CVE-2025-54068"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/livewire/livewire@3.6.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-81887 affects version 3.6.3-p1+tuxcare of livewire/livewire.",
      "vulnerability": {
        "name": "CVE-2026-81887"
      },
      "action_statement": "Vulnerability CVE-2026-81887 affects version 3.6.3-p1+tuxcare of livewire/livewire."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@10.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@10.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 10.4.2-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/flysystem@1.1.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/flysystem@1.1.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32708 is fixed in version 1.1.10-p1+tuxcare of league/flysystem.",
      "vulnerability": {
        "name": "CVE-2021-32708"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.5.8-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.5.8-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.5.8-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.6.40-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.6.40-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.6.40-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40-p1+tuxcare uses SwiftMailer 6.3.0, not the Symfony Mailer targeted by GHSA-5vg9-5847-vvmq. SwiftMailer's Egulias EmailValidator provides CRLF validation that prevents the vulnerability pattern from manifesting.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.6.40-p1+tuxcare uses SwiftMailer 6.3.0, not the Symfony Mailer targeted by GHSA-5vg9-5847-vvmq. SwiftMailer's Egulias EmailValidator provides CRLF validation that prevents the vulnerability pattern from manifesting."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.6.40-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40 does not have the vulnerable LocalFilesystemAdapter class or signed URL generation for local filesystem. The feature was introduced in Laravel 11+ (September 2024), years after this version. The FilesystemAdapter.temporaryUrl() method explicitly throws RuntimeException for local adapters - the feature is unsupported.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.6.40 does not have the vulnerable LocalFilesystemAdapter class or signed URL generation for local filesystem. The feature was introduced in Laravel 11+ (September 2024), years after this version. The FilesystemAdapter.temporaryUrl() method explicitly throws RuntimeException for local adapters - the feature is unsupported."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.6.40-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 6.20.45-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 does not affect version 6.20.45-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 6.20.45-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 6.20.45-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "action_statement": "Vulnerability CVE-2025-57811 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "action_statement": "Vulnerability CVE-2026-25494 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "action_statement": "Vulnerability CVE-2026-25498 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "action_statement": "Vulnerability CVE-2026-27129 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "action_statement": "Vulnerability CVE-2026-29113 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "action_statement": "Vulnerability CVE-2026-31859 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "action_statement": "Vulnerability CVE-2026-33158 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "action_statement": "Vulnerability CVE-2026-33159 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "action_statement": "Vulnerability CVE-2026-33160 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "action_statement": "Vulnerability CVE-2026-33161 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "action_statement": "Vulnerability CVE-2026-56383 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "action_statement": "Vulnerability CVE-2026-56385 affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      },
      "action_statement": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      },
      "action_statement": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p6+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p6+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p6+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p6+tuxcare of craftcms/cms."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p6+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p6+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-51651 is fixed in version 3.263.4-p2+tuxcare of aws/aws-sdk-php.",
      "vulnerability": {
        "name": "CVE-2023-51651"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14761 affects version 3.263.4-p2+tuxcare of aws/aws-sdk-php, and is fixed in 3.263.4-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-14761"
      },
      "action_statement": "Vulnerability CVE-2025-14761 affects version 3.263.4-p2+tuxcare of aws/aws-sdk-php, and is fixed in 3.263.4-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/aws/aws-sdk-php@3.263.4-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-27qh-8cxx-2cr5 is fixed in version 3.263.4-p2+tuxcare of aws/aws-sdk-php.",
      "vulnerability": {
        "name": "GHSA-27qh-8cxx-2cr5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@12.4.5-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@12.4.5-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 12.4.5-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p2+tuxcare.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      },
      "action_statement": "Vulnerability AIKIDO-2026-10659 affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.8.38-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.8.38-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      },
      "action_statement": "Vulnerability CVE-2024-52301 affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.8.38-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 5.8.38-p1+tuxcare of laravel/framework, and is fixed in 5.8.38-p5+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.8.38-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.8.38-p4+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects LocalFilesystemAdapter's temporary signed URL functionality, which does not exist in Laravel 5.8. This feature was introduced in Laravel 11+. The target version only supports temporary URLs for cloud storage (S3/Rackspace), which use different mechanisms that are not vulnerable to this path encoding issue."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.8.38-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.8.38-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.8.38-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 8.83.29-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p3+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.83.29-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mailer@v7.4.8-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mailer@v7.4.8-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45068 is fixed in version v7.4.8-p1+tuxcare of symfony/mailer.",
      "vulnerability": {
        "name": "CVE-2026-45068"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 7.30.7-p1+tuxcare of laravel/framework, and is fixed in 7.30.7-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 7.30.7-p1+tuxcare of laravel/framework, and is fixed in 7.30.7-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 7.30.7-p1+tuxcare of laravel/framework, and is fixed in 7.30.7-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 7.30.7-p1+tuxcare of laravel/framework, and is fixed in 7.30.7-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-45440"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      },
      "action_statement": "Vulnerability CVE-2025-13080 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      },
      "action_statement": "Vulnerability CVE-2025-13081 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      },
      "action_statement": "Vulnerability CVE-2025-13082 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      },
      "action_statement": "Vulnerability CVE-2025-13083 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      },
      "action_statement": "Vulnerability CVE-2026-6365 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      },
      "action_statement": "Vulnerability CVE-2026-6366 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      },
      "action_statement": "Vulnerability CVE-2026-9082 affects version 9.5.11-p1+tuxcare of drupal/core, and is fixed in 9.5.11-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p1+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6CCV-8FGF-CJPW"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p1+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      },
      "impact_statement": "already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      },
      "action_statement": "Vulnerability CVE-2012-4451 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      },
      "action_statement": "Vulnerability CVE-2014-2681 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      },
      "action_statement": "Vulnerability CVE-2014-2682 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      },
      "action_statement": "Vulnerability CVE-2014-2683 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      },
      "action_statement": "Vulnerability CVE-2015-3154 affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      },
      "action_statement": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      },
      "action_statement": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.11.0-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.11.0-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.10.6-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10189 is fixed in version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "AIKIDO-2024-10189"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48555 affects version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 9.12.4-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48555"
      },
      "action_statement": "Vulnerability CVE-2026-48555 affects version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 9.12.4-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@9.12.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48557 affects version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 9.12.4-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48557"
      },
      "action_statement": "Vulnerability CVE-2026-48557 affects version 9.12.4-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 9.12.4-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@5.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@5.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51736 is fixed in version 5.4.45-p1+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2024-51736"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@5.4.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@5.4.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24739 affects version 5.4.45-p1+tuxcare of symfony/process, and is fixed in 5.4.45-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24739"
      },
      "action_statement": "Vulnerability CVE-2026-24739 affects version 5.4.45-p1+tuxcare of symfony/process, and is fixed in 5.4.45-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-30130 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2021-30130"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-52892 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2023-52892"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27354 affects version 0.3.10-p2+tuxcare of phpseclib/phpseclib, and is fixed in 0.3.10-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27354"
      },
      "action_statement": "Vulnerability CVE-2024-27354 affects version 0.3.10-p2+tuxcare of phpseclib/phpseclib, and is fixed in 0.3.10-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27355 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-27355"
      },
      "impact_statement": "already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32935 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-32935"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40194 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-40194"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44167 is fixed in version 0.3.10-p2+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-44167"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55599 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55599"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84308 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. not_affected \u2014 The target repository (phpseclib 0.3.10-p3+tuxcare) is not affected by CVE-2026-84308. This CVE targets a timing side-channel vulnerability in phpseclib 3.0.56's pure-PHP X25519/Curve25519 elliptic curve implementation. Version 0.3.10 predates elliptic curve cryptography support entirely and does not contain any of the vulnerable code paths, classes, or operations described in the CVE. Exhausti...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-84308"
      },
      "impact_statement": "not_affected \u2014 The target repository (phpseclib 0.3.10-p3+tuxcare) is not affected by CVE-2026-84308. This CVE targets a timing side-channel vulnerability in phpseclib 3.0.56's pure-PHP X25519/Curve25519 elliptic curve implementation. Version 0.3.10 predates elliptic curve cryptography support entirely and does not contain any of the vulnerable code paths, classes, or operations described in the CVE. Exhausti..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-m557-wrgg-6rp4 does not affect version 0.3.10-p2+tuxcare of phpseclib/phpseclib. not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-m557-wrgg-6rp4"
      },
      "impact_statement": "not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@9.5.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@9.5.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 9.5.28-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-14775 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2017-14775"
      },
      "action_statement": "Vulnerability CVE-2017-14775 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-16894 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2017-16894"
      },
      "action_statement": "Vulnerability CVE-2017-16894 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2018-15133"
      },
      "action_statement": "Vulnerability CVE-2018-15133 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      },
      "action_statement": "Vulnerability CVE-2020-19316 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      },
      "action_statement": "Vulnerability CVE-2020-24941 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      },
      "action_statement": "Vulnerability CVE-2021-21263 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      },
      "action_statement": "Vulnerability CVE-2024-52301 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "action_statement": "Vulnerability CVE-2025-27515 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      },
      "action_statement": "Vulnerability GHSA-4mg9-vhxq-vm7j affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch...",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7852-w36x-6mf6 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-7852-w36x-6mf6"
      },
      "action_statement": "Vulnerability GHSA-7852-w36x-6mf6 affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      },
      "action_statement": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      },
      "action_statement": "Vulnerability GHSA-x7p5-p2c9-phvg affects version 5.4.36-p1+tuxcare of laravel/framework, and is fixed in 5.4.36-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/webform_multifile@7.1.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/webform_multifile@7.1.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12848 is fixed in version 7.1.6-p1+tuxcare of drupal/webform_multifile.",
      "vulnerability": {
        "name": "CVE-2025-12848"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7809 does not affect version v2.16.1-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is Twig version 2.16.1, which contains the fix introduced in 1.20.0. The vulnerability allowed remote code execution via the _self variable in templates when Sandbox mode was enabled. The fix adds a type validation check in the displayBlock function that ensures template blocks must be instances of \\Twig\\Template, preventin...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2015-7809"
      },
      "impact_statement": "already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is Twig version 2.16.1, which contains the fix introduced in 1.20.0. The vulnerability allowed remote code execution via the _self variable in templates when Sandbox mode was enabled. The fix adds a type validation check in the displayBlock function that ensures template blocks must be instances of \\Twig\\Template, preventin..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-9942 does not affect version v2.16.1-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 has been fixed in Twig 2.16.1. The target contains the complete mitigation introduced in Twig 2.7.0 that prevents __toString() method calls from bypassing sandbox security policy restrictions.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2019-9942"
      },
      "impact_statement": "already_fixed \u2014 CVE-2019-9942 has been fixed in Twig 2.16.1. The target contains the complete mitigation introduced in Twig 2.7.0 that prevents __toString() method calls from bypassing sandbox security policy restrictions."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51754 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51755 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51755"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24425 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-24425"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46628 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46633 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46633"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46635 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46635"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46638 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47732 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-47732"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48805 does not affect version v2.16.1-p1+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48805 describes a sandbox bypass in Twig v3.26.0 where deprecated wrapper functions in src/Resources/core.php fail to forward sandbox state to refactored CoreExtension class methods. Target v2.16.1 uses a completely different architecture where the vulnerable delegation pattern does not exist. The functions twig_array_some() and twig_array_every() don't exist in v2.16.1, and twig_check...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48805"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-48805 describes a sandbox bypass in Twig v3.26.0 where deprecated wrapper functions in src/Resources/core.php fail to forward sandbox state to refactored CoreExtension class methods. Target v2.16.1 uses a completely different architecture where the vulnerable delegation pattern does not exist. The functions twig_array_some() and twig_array_every() don't exist in v2.16.1, and twig_check..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48806 affects version v2.16.1-p1+tuxcare of twig/twig, and is fixed in v2.16.1-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48806"
      },
      "action_statement": "Vulnerability CVE-2026-48806 affects version v2.16.1-p1+tuxcare of twig/twig, and is fixed in v2.16.1-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48807 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48807"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48808 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.16.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49981 is fixed in version v2.16.1-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-49981"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21544 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21544"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21547 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21547"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21549 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21549"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1022 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-1022"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1026 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-1026"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3192 is fixed in version 4.4.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-3192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21544 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21544"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21547 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21547"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21549 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2024-21549"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1022 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-1022"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1026 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-1026"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@3.61.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3192 is fixed in version 3.61.0-p2+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-3192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3007 is fixed in version 2.5.6-p2+tuxcare of zendframework/zend-http.",
      "vulnerability": {
        "name": "CVE-2021-3007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-cg8w-5jrc-675g is fixed in version 2.5.6-p2+tuxcare of zendframework/zend-http.",
      "vulnerability": {
        "name": "GHSA-cg8w-5jrc-675g"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zend-http@2.5.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f6p5-76fp-m248 does not affect version 2.5.6-p2+tuxcare of zendframework/zend-http. already_fixed \u2014 The target repository has already been patched. The vulnerability (GHSA-f6p5-76fp-m248 / ZF2018-01) was fixed in commit 80b11a4c9a711ec50bca8892af91f809a2d1b958 ('Backport GHSA-cg8w-5jrc-675g to 2.5.6') dated 2026-06-24, which removed the code that unconditionally reads X-Rewrite-Url and X-Original-Url headers. The fix is identical to the upstream patch.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-f6p5-76fp-m248"
      },
      "impact_statement": "already_fixed \u2014 The target repository has already been patched. The vulnerability (GHSA-f6p5-76fp-m248 / ZF2018-01) was fixed in commit 80b11a4c9a711ec50bca8892af91f809a2d1b958 ('Backport GHSA-cg8w-5jrc-675g to 2.5.6') dated 2026-06-24, which removed the code that unconditionally reads X-Rewrite-Url and X-Original-Url headers. The fix is identical to the upstream patch."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 7.30.7-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 7.30.7-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 7.30.7-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@7.30.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 7.30.7-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 7.30.7-p1+tuxcare is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in the LocalFilesystemAdapter class which provides temporary signed URL generation for local filesystems. This class and the associated local file serving feature were introduced in Laravel 9.x and do not exist in Laravel 7.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10189 is fixed in version 10.15.0-p2+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "AIKIDO-2024-10189"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48555 is fixed in version 10.15.0-p2+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "CVE-2026-48555"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48557 is fixed in version 10.15.0-p2+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "CVE-2026-48557"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      },
      "action_statement": "Vulnerability CVE-2011-1939 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      },
      "action_statement": "Vulnerability CVE-2012-4451 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      },
      "action_statement": "Vulnerability CVE-2012-5657 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      },
      "action_statement": "Vulnerability CVE-2012-6531 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      },
      "action_statement": "Vulnerability CVE-2014-2681 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      },
      "action_statement": "Vulnerability CVE-2014-2682 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      },
      "action_statement": "Vulnerability CVE-2014-2683 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      },
      "action_statement": "Vulnerability CVE-2014-8088 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      },
      "action_statement": "Vulnerability CVE-2014-8089 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      },
      "action_statement": "Vulnerability CVE-2015-3154 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      },
      "action_statement": "Vulnerability CVE-2015-5723 affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      },
      "action_statement": "Vulnerability GHSA-229x-22xc-2f2w affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      },
      "action_statement": "Vulnerability GHSA-2x36-qhx3-7m5f affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      },
      "action_statement": "Vulnerability GHSA-9v78-h226-2rmq affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      },
      "action_statement": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      },
      "action_statement": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      },
      "action_statement": "Vulnerability GHSA-mhpx-3rv8-wrjm affects version 1.11.0-p1+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.11.0-p1+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51754 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51755 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-51755"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46628 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46628"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46633 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46633"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46635 does not affect version v1.44.8-p2+tuxcare of twig/twig. not_affected \u2014 The `column` filter that is the subject of CVE-2026-46635 does not exist in Twig 1.44.8. This version is part of the Twig 1.x series (CHANGELOG notes v1.44.6 as \"Last version for the 1.x series\"), while the column filter was introduced in Twig 2.x. Without this filter, the vulnerable code path (template calls column filter \u2192 delegates to array_column() \u2192 reads object properties bypassing sandbo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-46635"
      },
      "impact_statement": "not_affected \u2014 The `column` filter that is the subject of CVE-2026-46635 does not exist in Twig 1.44.8. This version is part of the Twig 1.x series (CHANGELOG notes v1.44.6 as \"Last version for the 1.x series\"), while the column filter was introduced in Twig 2.x. Without this filter, the vulnerable code path (template calls column filter \u2192 delegates to array_column() \u2192 reads object properties bypassing sandbo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46638 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-46638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47732 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-47732"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48805 does not affect version v1.44.8-p2+tuxcare of twig/twig. not_affected \u2014 Target Twig 1.44.8 is NOT AFFECTED by CVE-2026-48805. This vulnerability is specific to Twig 3.26.0+ architectural changes that introduced per-source sandbox state with boolean parameters. The three vulnerable deprecated wrapper functions mentioned in the CVE (twig_array_some(), twig_array_every(), twig_check_arrow_in_sandbox()) do not exist in Twig 1.44.x. The equivalent functionality in Twig ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48805"
      },
      "impact_statement": "not_affected \u2014 Target Twig 1.44.8 is NOT AFFECTED by CVE-2026-48805. This vulnerability is specific to Twig 3.26.0+ architectural changes that introduced per-source sandbox state with boolean parameters. The three vulnerable deprecated wrapper functions mentioned in the CVE (twig_array_some(), twig_array_every(), twig_check_arrow_in_sandbox()) do not exist in Twig 1.44.x. The equivalent functionality in Twig ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48806 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48806"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48807 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-48807"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48808 does not affect version v1.44.8-p2+tuxcare of twig/twig. not_affected \u2014 Twig v1.44.8 is not affected by CVE-2026-48808. The vulnerability concerns a sandbox bypass in the `column` filter when sandboxing is enabled via `SourcePolicyInterface`. However, v1.44.8 lacks both the column filter feature (introduced in later Twig versions 2.x/3.x) and the SourcePolicyInterface mechanism. Exhaustive searches across the codebase confirmed no column filter registration in Core...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48808"
      },
      "impact_statement": "not_affected \u2014 Twig v1.44.8 is not affected by CVE-2026-48808. The vulnerability concerns a sandbox bypass in the `column` filter when sandboxing is enabled via `SourcePolicyInterface`. However, v1.44.8 lacks both the column filter feature (introduced in later Twig versions 2.x/3.x) and the SourcePolicyInterface mechanism. Exhaustive searches across the codebase confirmed no column filter registration in Core..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v1.44.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49981 is fixed in version v1.44.8-p2+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2026-49981"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/gdpr@3.1.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/gdpr@3.1.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31689 is fixed in version 3.1.0-p1+tuxcare of drupal/gdpr.",
      "vulnerability": {
        "name": "CVE-2025-31689"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-30130 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2021-30130"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-52892 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2023-52892"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27354 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2024-27354"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27355 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-27355"
      },
      "impact_statement": "already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32935 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-32935"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40194 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-40194"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44167 is fixed in version 0.3.10-p3+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-44167"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55599 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55599"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84308 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. not_affected \u2014 The target repository (phpseclib 0.3.10-p3+tuxcare) is not affected by CVE-2026-84308. This CVE targets a timing side-channel vulnerability in phpseclib 3.0.56's pure-PHP X25519/Curve25519 elliptic curve implementation. Version 0.3.10 predates elliptic curve cryptography support entirely and does not contain any of the vulnerable code paths, classes, or operations described in the CVE. Exhausti...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-84308"
      },
      "impact_statement": "not_affected \u2014 The target repository (phpseclib 0.3.10-p3+tuxcare) is not affected by CVE-2026-84308. This CVE targets a timing side-channel vulnerability in phpseclib 3.0.56's pure-PHP X25519/Curve25519 elliptic curve implementation. Version 0.3.10 predates elliptic curve cryptography support entirely and does not contain any of the vulnerable code paths, classes, or operations described in the CVE. Exhausti..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-m557-wrgg-6rp4 does not affect version 0.3.10-p3+tuxcare of phpseclib/phpseclib. not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-m557-wrgg-6rp4"
      },
      "impact_statement": "not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/illuminate/database@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/database@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p3+tuxcare of illuminate/database.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/illuminate/database@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/database@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p3+tuxcare of illuminate/database.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@7.5.20-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@7.5.20-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 7.5.20-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24775 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2022-24775"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29197 does not affect version 1.4.2-p1+tuxcare of guzzlehttp/psr7. Version 1.4.2 is not vulnerable. Summary: CVE-2023-29197 does NOT affect version 1.4.2. The vulnerable code (header validation regex without /D modifier) was introduced ~3 years AFTER this version (in commit 092dbc2 on 2020-01-09, first appearing in version 2.0.0). Version 1.4.2 predates the introduction of the assertHeader() and assertValue() validation methods entirely. Since the vulnerable code pattern was never present in this version, it is not vulnerable to this specific CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-29197"
      },
      "impact_statement": "Version 1.4.2 is not vulnerable. Summary: CVE-2023-29197 does NOT affect version 1.4.2. The vulnerable code (header validation regex without /D modifier) was introduced ~3 years AFTER this version (in commit 092dbc2 on 2020-01-09, first appearing in version 2.0.0). Version 1.4.2 predates the introduction of the assertHeader() and assertValue() validation methods entirely. Since the vulnerable code pattern was never present in this version, it is not vulnerable to this specific CVE."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48998 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.4.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48998"
      },
      "action_statement": "Vulnerability CVE-2026-48998 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.4.2-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49214 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-49214"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55766 is fixed in version 1.4.2-p1+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-55766"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59882 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.4.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59882"
      },
      "action_statement": "Vulnerability CVE-2026-59882 affects version 1.4.2-p1+tuxcare of guzzlehttp/psr7, and is fixed in 1.4.2-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46734 is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2025-46734"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p4+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p4+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p4+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-c2pc-g5qf-rfrf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p4+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p4+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf is fixed in version 1.6.7-p4+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p4+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p4+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p3+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-14775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-16894"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2018-15133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p3+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch...",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-7852-w36x-6mf6"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p3+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      },
      "action_statement": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.4.36-p3+tuxcare of laravel/framework, and is fixed in 5.4.36-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      },
      "action_statement": "Vulnerability CVE-2012-4451 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      },
      "action_statement": "Vulnerability CVE-2014-2681 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      },
      "action_statement": "Vulnerability CVE-2014-2682 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      },
      "action_statement": "Vulnerability CVE-2014-2683 affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      },
      "action_statement": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      },
      "action_statement": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.11.0-p3+tuxcare of zendframework/zendframework1, and is fixed in 1.11.0-p4+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.11.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.11.0-p3+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 6.20.45-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 does not affect version 6.20.45-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 6.20.45-p1+tuxcare of laravel/framework, and is fixed in 6.20.45-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 6.20.45-p1+tuxcare of laravel/framework, and is fixed in 6.20.45-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 6.20.45-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45065 is fixed in version v3.4.47-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-45065"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/routing@v3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48784 is fixed in version v3.4.47-p1+tuxcare of symfony/routing.",
      "vulnerability": {
        "name": "CVE-2026-48784"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-50345 affects version 2.8.52-p1+tuxcare of symfony/http-foundation, and is fixed in 2.8.52-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-50345"
      },
      "action_statement": "Vulnerability CVE-2024-50345 affects version 2.8.52-p1+tuxcare of symfony/http-foundation, and is fixed in 2.8.52-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@2.8.52-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64500 is fixed in version 2.8.52-p1+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2025-64500"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 10.50.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.50.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.50.2-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-30130 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2021-30130"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-52892 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2023-52892"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27354 affects version 0.3.10-p1+tuxcare of phpseclib/phpseclib, and is fixed in 0.3.10-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-27354"
      },
      "action_statement": "Vulnerability CVE-2024-27354 affects version 0.3.10-p1+tuxcare of phpseclib/phpseclib, and is fixed in 0.3.10-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27355 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-27355"
      },
      "impact_statement": "already_fixed \u2014 The target repository (phpseclib 0.3.10-p2+tuxcare) already contains a fix for CVE-2024-27355. TuxCare applied a backport in commit f47d51d that limits OID length to 128 bytes, which is stricter than the upstream fix (4096 bytes). This fix addresses both CVE-2024-27355 and its bypass vulnerability CVE-2026-44167."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32935 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-32935"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40194 affects version 0.3.10-p1+tuxcare of phpseclib/phpseclib, and is fixed in 0.3.10-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40194"
      },
      "action_statement": "Vulnerability CVE-2026-40194 affects version 0.3.10-p1+tuxcare of phpseclib/phpseclib, and is fixed in 0.3.10-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-44167 is fixed in version 0.3.10-p1+tuxcare of phpseclib/phpseclib.",
      "vulnerability": {
        "name": "CVE-2026-44167"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55599 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55599"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55599 (SSRF via AIA URL fetching) does not affect phpseclib version 0.3.10. The vulnerable AIA URL fetching feature (testForIntermediate() calling fetchURL() with fsockopen()) was introduced in later versions (3.x/4.x) and does not exist in this older codebase. While the target parses AIA extensions, it never acts on the URL data to make network connections."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-84308 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. not_affected \u2014 The target repository (phpseclib 0.3.10-p3+tuxcare) is not affected by CVE-2026-84308. This CVE targets a timing side-channel vulnerability in phpseclib 3.0.56's pure-PHP X25519/Curve25519 elliptic curve implementation. Version 0.3.10 predates elliptic curve cryptography support entirely and does not contain any of the vulnerable code paths, classes, or operations described in the CVE. Exhausti...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-84308"
      },
      "impact_statement": "not_affected \u2014 The target repository (phpseclib 0.3.10-p3+tuxcare) is not affected by CVE-2026-84308. This CVE targets a timing side-channel vulnerability in phpseclib 3.0.56's pure-PHP X25519/Curve25519 elliptic curve implementation. Version 0.3.10 predates elliptic curve cryptography support entirely and does not contain any of the vulnerable code paths, classes, or operations described in the CVE. Exhausti..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpseclib/phpseclib@0.3.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-m557-wrgg-6rp4 does not affect version 0.3.10-p1+tuxcare of phpseclib/phpseclib. not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-m557-wrgg-6rp4"
      },
      "impact_statement": "not_affected \u2014 phpseclib version 0.3.10-p2+tuxcare is not affected by the SSRF vulnerability (GHSA-m557-wrgg-6rp4). The vulnerable URL fetching functionality introduced in later versions (3.0.x, 4.0.x) does not exist in this legacy 0.3.x branch. While the target can parse AIA extensions from certificates, no code path uses these extensions to make network connections during certificate validation."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laminas/laminas-http@2.5.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laminas/laminas-http@2.5.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3007 is fixed in version 2.5.6-p1+tuxcare of laminas/laminas-http.",
      "vulnerability": {
        "name": "CVE-2021-3007"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 is fixed in version 6.3.3-p1+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      },
      "action_statement": "Vulnerability CVE-2026-55568 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      },
      "action_statement": "Vulnerability CVE-2026-55767 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      },
      "action_statement": "Vulnerability CVE-2026-59883 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      },
      "action_statement": "Vulnerability CVE-2026-67339 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      },
      "action_statement": "Vulnerability CVE-2026-67353 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      },
      "action_statement": "Vulnerability CVE-2026-67354 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      },
      "action_statement": "Vulnerability CVE-2026-67355 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      },
      "action_statement": "Vulnerability GHSA-94pj-82f3-465w affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      },
      "action_statement": "Vulnerability GHSA-h95v-h523-3mw8 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.3.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      },
      "action_statement": "Vulnerability GHSA-wm3w-8rrp-j577 affects version 6.3.3-p1+tuxcare of guzzlehttp/guzzle, and is fixed in 6.3.3-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-24775 is fixed in version 1.4.2-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2022-24775"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29197 does not affect version 1.4.2-p2+tuxcare of guzzlehttp/psr7. Version 1.4.2 is not vulnerable. Summary: CVE-2023-29197 does NOT affect version 1.4.2. The vulnerable code (header validation regex without /D modifier) was introduced ~3 years AFTER this version (in commit 092dbc2 on 2020-01-09, first appearing in version 2.0.0). Version 1.4.2 predates the introduction of the assertHeader() and assertValue() validation methods entirely. Since the vulnerable code pattern was never present in this version, it is not vulnerable to this specific CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-29197"
      },
      "impact_statement": "Version 1.4.2 is not vulnerable. Summary: CVE-2023-29197 does NOT affect version 1.4.2. The vulnerable code (header validation regex without /D modifier) was introduced ~3 years AFTER this version (in commit 092dbc2 on 2020-01-09, first appearing in version 2.0.0). Version 1.4.2 predates the introduction of the assertHeader() and assertValue() validation methods entirely. Since the vulnerable code pattern was never present in this version, it is not vulnerable to this specific CVE."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48998 is fixed in version 1.4.2-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-48998"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49214 is fixed in version 1.4.2-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-49214"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55766 is fixed in version 1.4.2-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-55766"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/psr7@1.4.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59882 is fixed in version 1.4.2-p2+tuxcare of guzzlehttp/psr7.",
      "vulnerability": {
        "name": "CVE-2026-59882"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 8.83.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 8.83.29-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.83.29-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.83.29-p2+tuxcare of laravel/framework, and is fixed in 8.83.29-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 8.83.29-p2+tuxcare of laravel/framework, and is fixed in 8.83.29-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.83.29-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.83.29-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.83.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerable component (LocalFilesystemAdapter with local filesystem signed URL serving) was introduced in Laravel 11.x/12.x and does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-8379 is fixed in version 2.10.24-p2+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2015-8379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-15400 is fixed in version 2.10.24-p2+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2020-15400"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48820 is fixed in version 2.10.24-p2+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2026-48820"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-77634 affects version 2.10.24-p2+tuxcare of cakephp/cakephp, and is fixed in 2.10.24-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-77634"
      },
      "action_statement": "Vulnerability CVE-2026-77634 affects version 2.10.24-p2+tuxcare of cakephp/cakephp, and is fixed in 2.10.24-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-79752 does not affect version 2.10.24-p2+tuxcare of cakephp/cakephp. not_affected \u2014 CakePHP 2.10.24 is not affected by CVE-2026-79752. The vulnerable FunctionsBuilder class and its methods (cast, extract, datePart, dateAdd) do not exist in this version. The CVE describes SQL injection in CakePHP's Query Builder system introduced in version 3.x. CakePHP 2.x uses a different architecture (DboSource with active record pattern) that predates the Query Builder. Exhaustive search of...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-79752"
      },
      "impact_statement": "not_affected \u2014 CakePHP 2.10.24 is not affected by CVE-2026-79752. The vulnerable FunctionsBuilder class and its methods (cast, extract, datePart, dateAdd) do not exist in this version. The CVE describes SQL injection in CakePHP's Query Builder system introduced in version 3.x. CakePHP 2.x uses a different architecture (DboSource with active record pattern) that predates the Query Builder. Exhaustive search of..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-14775 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-14775"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-16894 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2017-16894"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2018-15133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.4.36-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.4.36-p4+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.4.36-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch...",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36-p4+tuxcare uses SwiftMailer, not Symfony Mailer. The CVE (GHSA-5vg9-5847-vvmq) is specific to 'how Symfony Mailer and Symfony Mime handle certain character sequences'. SwiftMailer has RFC 2822 grammar validation that should reject CRLF characters in email addresses (except as proper folding whitespace), providing a different defense mechanism than what the Laravel 12.x/13.x patch..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-7852-w36x-6mf6 is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-7852-w36x-6mf6"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.4.36-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.4.36 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability requires the LocalFilesystemAdapter with temporary signed URL support via temporarySignedRoute(), a feature introduced in Laravel 9+. Laravel 5.4 uses FilesystemAdapter which explicitly throws RuntimeException for local storage temporary URLs, stating 'This driver does not support creating temporary URLs.' The vulnerable c..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.4.36-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.4.36-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p4+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/shs@7.1.10-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/shs@7.1.10-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4929 is fixed in version 7.1.10-p1+tuxcare of drupal/shs.",
      "vulnerability": {
        "name": "CVE-2026-4929"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@6.5.14-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@6.5.14-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 6.5.14-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 11.51.0-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 11.51.0-p1+tuxcare of laravel/framework, and is fixed in 11.51.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 11.51.0-p1+tuxcare of laravel/framework, and is fixed in 11.51.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.51.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 11.51.0-p1+tuxcare of laravel/framework, and is fixed in 11.51.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "action_statement": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 11.51.0-p1+tuxcare of laravel/framework, and is fixed in 11.51.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "action_statement": "Vulnerability CVE-2025-57811 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      },
      "action_statement": "Vulnerability CVE-2025-68437 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "action_statement": "Vulnerability CVE-2026-25494 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "action_statement": "Vulnerability CVE-2026-25496 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "action_statement": "Vulnerability CVE-2026-25498 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      },
      "action_statement": "Vulnerability CVE-2026-27127 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "action_statement": "Vulnerability CVE-2026-27129 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "action_statement": "Vulnerability CVE-2026-29113 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "action_statement": "Vulnerability CVE-2026-31859 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "action_statement": "Vulnerability CVE-2026-32267 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "action_statement": "Vulnerability CVE-2026-33158 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "action_statement": "Vulnerability CVE-2026-33159 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "action_statement": "Vulnerability CVE-2026-33160 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "action_statement": "Vulnerability CVE-2026-33161 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      },
      "action_statement": "Vulnerability CVE-2026-55790 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "action_statement": "Vulnerability CVE-2026-56383 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      },
      "action_statement": "Vulnerability CVE-2026-56384 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "action_statement": "Vulnerability CVE-2026-56385 affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      },
      "action_statement": "Vulnerability GHSA-3m9m-24vh-39wx affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      },
      "action_statement": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      },
      "action_statement": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p2+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p2+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p2+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p2+tuxcare of craftcms/cms."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      },
      "action_statement": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p2+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46734 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-46734"
      },
      "action_statement": "Vulnerability CVE-2025-46734 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      },
      "action_statement": "Vulnerability CVE-2026-30838 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p1+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      },
      "action_statement": "Vulnerability CVE-2026-71478 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      },
      "action_statement": "Vulnerability CVE-2026-71488 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p1+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-c2pc-g5qf-rfrf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      },
      "action_statement": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      },
      "action_statement": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p1+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-8379 is fixed in version 2.10.24-p1+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2015-8379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-15400 is fixed in version 2.10.24-p1+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2020-15400"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48820 affects version 2.10.24-p1+tuxcare of cakephp/cakephp, and is fixed in 2.10.24-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48820"
      },
      "action_statement": "Vulnerability CVE-2026-48820 affects version 2.10.24-p1+tuxcare of cakephp/cakephp, and is fixed in 2.10.24-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-77634 affects version 2.10.24-p1+tuxcare of cakephp/cakephp, and is fixed in 2.10.24-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-77634"
      },
      "action_statement": "Vulnerability CVE-2026-77634 affects version 2.10.24-p1+tuxcare of cakephp/cakephp, and is fixed in 2.10.24-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-79752 does not affect version 2.10.24-p1+tuxcare of cakephp/cakephp. not_affected \u2014 CakePHP 2.10.24 is not affected by CVE-2026-79752. The vulnerable FunctionsBuilder class and its methods (cast, extract, datePart, dateAdd) do not exist in this version. The CVE describes SQL injection in CakePHP's Query Builder system introduced in version 3.x. CakePHP 2.x uses a different architecture (DboSource with active record pattern) that predates the Query Builder. Exhaustive search of...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-79752"
      },
      "impact_statement": "not_affected \u2014 CakePHP 2.10.24 is not affected by CVE-2026-79752. The vulnerable FunctionsBuilder class and its methods (cast, extract, datePart, dateAdd) do not exist in this version. The CVE describes SQL injection in CakePHP's Query Builder system introduced in version 3.x. CakePHP 2.x uses a different architecture (DboSource with active record pattern) that predates the Query Builder. Exhaustive search of..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/coffee@7.2.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/coffee@7.2.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-13247 is fixed in version 7.2.3-p1+tuxcare of drupal/coffee.",
      "vulnerability": {
        "name": "CVE-2024-13247"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.2-p3+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is a false positive for laravel/framework 8.12.2-p3+tuxcare. false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l...",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.2-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.2-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.6.40-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.6.40-p2+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.6.40-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40-p1+tuxcare uses SwiftMailer 6.3.0, not the Symfony Mailer targeted by GHSA-5vg9-5847-vvmq. SwiftMailer's Egulias EmailValidator provides CRLF validation that prevents the vulnerability pattern from manifesting.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.6.40-p1+tuxcare uses SwiftMailer 6.3.0, not the Symfony Mailer targeted by GHSA-5vg9-5847-vvmq. SwiftMailer's Egulias EmailValidator provides CRLF validation that prevents the vulnerability pattern from manifesting."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.6.40-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40 does not have the vulnerable LocalFilesystemAdapter class or signed URL generation for local filesystem. The feature was introduced in Laravel 11+ (September 2024), years after this version. The FilesystemAdapter.temporaryUrl() method explicitly throws RuntimeException for local adapters - the feature is unsupported.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.6.40 does not have the vulnerable LocalFilesystemAdapter class or signed URL generation for local filesystem. The feature was introduced in Laravel 11+ (September 2024), years after this version. The FilesystemAdapter.temporaryUrl() method explicitly throws RuntimeException for local adapters - the feature is unsupported."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.6.40-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.6.40-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45133 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45133"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45304 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/yaml@v3.4.47-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45305 is fixed in version v3.4.47-p2+tuxcare of symfony/yaml.",
      "vulnerability": {
        "name": "CVE-2026-45305"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 12.58.0-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 12.58.0-p1+tuxcare of laravel/framework, and is fixed in 12.58.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 12.58.0-p1+tuxcare of laravel/framework, and is fixed in 12.58.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@12.58.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 12.58.0-p1+tuxcare of laravel/framework, and is fixed in 12.58.0-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "action_statement": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 12.58.0-p1+tuxcare of laravel/framework, and is fixed in 12.58.0-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-10074 does not affect version 5.4.12-p1+tuxcare of swiftmailer/swiftmailer. already_fixed \u2014 CVE-2016-10074 has already been fixed in target version 5.4.12. The vulnerability allowed command injection via backslash double quote sequences in email addresses. The fix is explicitly present in Swift_Transport_MailTransport class with the _isShellSafe() validation method that blocks shell-unsafe characters including backslash and double quote before passing email addresses to the mail() com...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2016-10074"
      },
      "impact_statement": "already_fixed \u2014 CVE-2016-10074 has already been fixed in target version 5.4.12. The vulnerability allowed command injection via backslash double quote sequences in email addresses. The fix is explicitly present in Swift_Transport_MailTransport class with the _isShellSafe() validation method that blocks shell-unsafe characters including backslash and double quote before passing email addresses to the mail() com..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/swiftmailer/swiftmailer@5.4.12-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-28859 is fixed in version 5.4.12-p1+tuxcare of swiftmailer/swiftmailer.",
      "vulnerability": {
        "name": "CVE-2024-28859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.2-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is a false positive for laravel/framework 8.12.2-p2+tuxcare. false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l...",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.2-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.2-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54370 is fixed in version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet.",
      "vulnerability": {
        "name": "CVE-2025-54370"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34084 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34084"
      },
      "action_statement": "Vulnerability CVE-2026-34084 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-35453 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-35453"
      },
      "action_statement": "Vulnerability CVE-2026-35453 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40296 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40296"
      },
      "action_statement": "Vulnerability CVE-2026-40296 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40863 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40863"
      },
      "action_statement": "Vulnerability CVE-2026-40863 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-40902 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-40902"
      },
      "action_statement": "Vulnerability CVE-2026-40902 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59931 does not affect version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet. not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-59931"
      },
      "impact_statement": "not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59932 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59932"
      },
      "action_statement": "Vulnerability CVE-2026-59932 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59933 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59933"
      },
      "action_statement": "Vulnerability CVE-2026-59933 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet, and is fixed in 4.5.0-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 10.48.29-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.29-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.48.29-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.48.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 10.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.48.29 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 10.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46734 is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2025-46734"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p5+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-c2pc-g5qf-rfrf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 is fixed in version 1.6.7-p5+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f8fg-pg57-v4j8 affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f8fg-pg57-v4j8"
      },
      "action_statement": "Vulnerability GHSA-f8fg-pg57-v4j8 affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 2.7.1-p2+tuxcare of league/commonmark, and is fixed in 2.7.1-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mh25-x5hq-wrqp is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mh25-x5hq-wrqp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.7.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mj63-m3rc-8ppr is fixed in version 2.7.1-p2+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mj63-m3rc-8ppr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25270 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25270"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25271 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25271"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25273 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25273"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25275 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25275"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25276 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25277 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25277"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-25278 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2022-25278"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-5256 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2023-5256"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@8.9.20-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@8.9.20-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw is fixed in version 8.9.20-p7+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/link@7.1.13-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/link@7.1.13-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 7.1.13-p1+tuxcare of drupal/link.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51736 is fixed in version 3.4.47-p1+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2024-51736"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@3.4.47-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@3.4.47-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24739 is fixed in version 3.4.47-p1+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2026-24739"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/colorbox@2.1.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/colorbox@2.1.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3900 is fixed in version 2.1.2-p1+tuxcare of drupal/colorbox.",
      "vulnerability": {
        "name": "CVE-2025-3900"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 10.50.2-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 10.50.2-p1+tuxcare of laravel/framework, and is fixed in 10.50.2-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 10.50.2-p1+tuxcare of laravel/framework, and is fixed in 10.50.2-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.50.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.50.2-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.50.2 does not contain the vulnerable local filesystem temporary signed URL feature. The LocalFilesystemAdapter class and its associated temporaryUrl()/temporaryUploadUrl() methods were introduced in Laravel 11.x. The vulnerable code path does not exist in this version."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f8fg-pg57-v4j8 is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-f8fg-pg57-v4j8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mh25-x5hq-wrqp is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mh25-x5hq-wrqp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@2.8.2-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mj63-m3rc-8ppr is fixed in version 2.8.2-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-mj63-m3rc-8ppr"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@4.8.10-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@4.8.10-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 4.8.10-p2+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.3-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.3-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.3 does not implement local filesystem temporary signed URLs. The vulnerability targets LocalFilesystemAdapter::temporaryUrl() which was introduced in Laravel 10+. In Laravel 8.x, calling temporaryUrl() on local filesystem throws RuntimeException, preventing the attack chain from completing."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.3-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.3-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45067 is fixed in version v6.4.37-p1+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45067"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v6.4.37-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45070 affects version v6.4.37-p1+tuxcare of symfony/mime, and is fixed in v6.4.37-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-45070"
      },
      "action_statement": "Vulnerability CVE-2026-45070 affects version v6.4.37-p1+tuxcare of symfony/mime, and is fixed in v6.4.37-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mailer@v6.4.34-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mailer@v6.4.34-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45068 is fixed in version v6.4.34-p1+tuxcare of symfony/mailer.",
      "vulnerability": {
        "name": "CVE-2026-45068"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-50345 is fixed in version 3.4.47-p3+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2024-50345"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/http-foundation@3.4.47-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-64500 is fixed in version 3.4.47-p3+tuxcare of symfony/http-foundation.",
      "vulnerability": {
        "name": "CVE-2025-64500"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/colorbox@7.2.19-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/colorbox@7.2.19-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3900 is fixed in version 7.2.19-p1+tuxcare of drupal/colorbox.",
      "vulnerability": {
        "name": "CVE-2025-3900"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/illuminate/view@5.4.36-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.4.36-p1+tuxcare of illuminate/view.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-15133 does not affect version 5.5.50-p1+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2018-15133"
      },
      "impact_statement": "Version 5.5.50 is not vulnerable. Summary: The target Laravel Framework v5.5.50-p2+tuxcare is NOT vulnerable to CVE-2018-15133. While the X-XSRF-TOKEN decryption feature exists, the vulnerable code pattern does not. The fix has been properly applied: the decrypt() method is called with false as the second parameter (via static::serialized()), preventing unsafe deserialization of the X-XSRF-TOKEN header value."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-19316 is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-19316"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-24941 is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2020-24941"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 affects version 5.5.50-p1+tuxcare of laravel/framework, and is fixed in 5.5.50-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "action_statement": "Vulnerability CVE-2021-43617 affects version 5.5.50-p1+tuxcare of laravel/framework, and is fixed in 5.5.50-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.5.50-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\"",
      "vulnerability": {
        "name": "CVE-2022-31279"
      },
      "impact_statement": "CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.5.50-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.5.50 uses SwiftMailer v6.3.0, not Symfony Mailer. The CVE explicitly describes a combination vulnerability requiring both Laravel's missing CRLF validation AND Symfony Mailer/Mime's specific handling of CRLF characters. Since the target uses a different mail library (SwiftMailer), the specific attack chain described in the CVE cannot be completed."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6jvx-8ch9-j2jr does not affect version 5.5.50-p1+tuxcare of laravel/framework. Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6jvx-8ch9-j2jr"
      },
      "impact_statement": "Version 5.5.50 is not vulnerable. Summary: The target repository (Laravel 5.5.50-p2+tuxcare) is NOT VULNERABLE to GHSA-6jvx-8ch9-j2jr (PHP object injection via cookie serialization). The repository has been patched with a global serialization disable mechanism that is more secure than the vendor's original selective fix."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.5.50-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 5.5.50 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 5.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.5.50-p1+tuxcare of laravel/framework, and is fixed in 5.5.50-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-qm5c-m76r-2hfr"
      },
      "action_statement": "Vulnerability GHSA-qm5c-m76r-2hfr affects version 5.5.50-p1+tuxcare of laravel/framework, and is fixed in 5.5.50-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@5.5.50-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.5.50-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.2-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 is a false positive for laravel/framework 8.12.2-p4+tuxcare. false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l...",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33347 describes a vulnerability in a Markdown Embed extension with components (DomainFilteringAdapter, OscaroteroEmbedAdapter, EmbedRenderer) that process oEmbed content. This repository is laravel/framework (Laravel PHP web application framework), which does not contain any of these components, does not have embed/oEmbed functionality, and does not depend on the affected embed/embed l..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.2-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.2 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability exists in Laravel 12.x's LocalFilesystemAdapter class which provides signed URL functionality for local filesystem storage. This feature does not exist in Laravel 8.12.2, which uses a different architecture where local filesystem adapters cannot generate temporary signed URLs."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.2-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.2-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/yajra/laravel-datatables-oracle@9.21.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/yajra/laravel-datatables-oracle@9.21.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10705 is fixed in version 9.21.2-p1+tuxcare of yajra/laravel-datatables-oracle.",
      "vulnerability": {
        "name": "AIKIDO-2025-10705"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-8379 is fixed in version 2.10.24-p3+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2015-8379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-15400 is fixed in version 2.10.24-p3+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2020-15400"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48820 is fixed in version 2.10.24-p3+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2026-48820"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-77634 is fixed in version 2.10.24-p3+tuxcare of cakephp/cakephp.",
      "vulnerability": {
        "name": "CVE-2026-77634"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/cakephp/cakephp@2.10.24-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-79752 does not affect version 2.10.24-p3+tuxcare of cakephp/cakephp. not_affected \u2014 CakePHP 2.10.24 is not affected by CVE-2026-79752. The vulnerable FunctionsBuilder class and its methods (cast, extract, datePart, dateAdd) do not exist in this version. The CVE describes SQL injection in CakePHP's Query Builder system introduced in version 3.x. CakePHP 2.x uses a different architecture (DboSource with active record pattern) that predates the Query Builder. Exhaustive search of...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-79752"
      },
      "impact_statement": "not_affected \u2014 CakePHP 2.10.24 is not affected by CVE-2026-79752. The vulnerable FunctionsBuilder class and its methods (cast, extract, datePart, dateAdd) do not exist in this version. The CVE describes SQL injection in CakePHP's Query Builder system introduced in version 3.x. CakePHP 2.x uses a different architecture (DboSource with active record pattern) that predates the Query Builder. Exhaustive search of..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2022-37251 (XSS via Drafts) affected Craft CMS 4.2.0.1 due to missing HTML encoding on user-controllable content (revision notes, tab names, group names, address titles). The vulnerability was fixed by upstream Craft CMS developers (Pixel & Tonic) in version 4.2.1 (released 2022-08-09) via commits that added Html::encode() to all affected output locations. Target version 4.18.7 inherits the...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "not_affected \u2014 CVE-2022-37251 (XSS via Drafts) affected Craft CMS 4.2.0.1 due to missing HTML encoding on user-controllable content (revision notes, tab names, group names, address titles). The vulnerability was fixed by upstream Craft CMS developers (Pixel & Tonic) in version 4.2.1 (released 2022-08-09) via commits that added Html::encode() to all affected output locations. Target version 4.18.7 inherits the..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS version 4.18.7, while CVE-2024-41800 specifically affects Craft CMS 5's TOTP (Time-based One-Time Password) two-factor authentication feature. The TOTP 2FA functionality does not exist in Craft CMS 4.x at all. Exhaustive searches across the entire codebase found no TOTP-related code, no Google2FA library dependency, no auth/methods directory structure, no Auth...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS version 4.18.7, while CVE-2024-41800 specifically affects Craft CMS 5's TOTP (Time-based One-Time Password) two-factor authentication feature. The TOTP 2FA functionality does not exist in Craft CMS 4.x at all. Exhaustive searches across the entire codebase found no TOTP-related code, no Google2FA library dependency, no auth/methods directory structure, no Auth..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. CVE-2024-52293 is NOT present in the target. The vulnerability required missing normalizePath() in FileHelper::absolutePath() line 136, allowing path traversal sequences like `../templates/poc` to bypass system directory security checks. The target code contains the upstream vendor's fix: `return static::normalizePath($from . $ds . $to, $ds);` which resolves traversal sequences before the path is used in security validations. This fix was introduced in upstream Craft CMS version 4.12.2 (commit 123e48a696 by brandon@pixelandtonic.com on 2024-09-11). The target version 4.18.7 naturally includes all fixes from 4.12.2. TuxCare onboarded the pre-fixed version 4.18.7; there is no separate TuxCare backport for this CVE on this version line.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 is NOT present in the target. The vulnerability required missing normalizePath() in FileHelper::absolutePath() line 136, allowing path traversal sequences like `../templates/poc` to bypass system directory security checks. The target code contains the upstream vendor's fix: `return static::normalizePath($from . $ds . $to, $ds);` which resolves traversal sequences before the path is used in security validations. This fix was introduced in upstream Craft CMS version 4.12.2 (commit 123e48a696 by brandon@pixelandtonic.com on 2024-09-11). The target version 4.18.7 naturally includes all fixes from 4.12.2. TuxCare onboarded the pre-fixed version 4.18.7; there is no separate TuxCare backport for this CVE on this version line."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-23209 fix a19d46be78a9 by brandon@pixelandtonic.com (2025-07-07) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-23209 fix a19d46be78a9 by brandon@pixelandtonic.com (2025-07-07) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. CVE-2025-32432 RCE vulnerability is NOT present in target version 4.18.7. The upstream vendor (Pixel & Tonic) fixed this type confusion vulnerability in commit e1c85441 (2025-04-10) by adding string type validation for the 'handle' parameter in AssetsController::actionGenerateTransform(). This fix was included in upstream release 4.18.7 (2026-08-18), which TuxCare subsequently onboarded to ELS on 2026-09-07. The target code at HEAD (b16f3f8a9b) contains the complete fix: lines 1208-1210 validate that $handle is a string before use, exactly matching the vendor patch. The CVE affects versions 4.0.0-RC1 to before 4.14.15; target version 4.18.7 is after the fixed version. Attribution: upstream vendor fix (no TuxCare authorship signal).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "CVE-2025-32432 RCE vulnerability is NOT present in target version 4.18.7. The upstream vendor (Pixel & Tonic) fixed this type confusion vulnerability in commit e1c85441 (2025-04-10) by adding string type validation for the 'handle' parameter in AssetsController::actionGenerateTransform(). This fix was included in upstream release 4.18.7 (2026-08-18), which TuxCare subsequently onboarded to ELS on 2026-09-07. The target code at HEAD (b16f3f8a9b) contains the complete fix: lines 1208-1210 validate that $handle is a string before use, exactly matching the vendor patch. The CVE affects versions 4.0.0-RC1 to before 4.14.15; target version 4.18.7 is after the fixed version. Attribution: upstream vendor fix (no TuxCare authorship signal)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Not affected: CVE-2025-46731 affects Craft CMS 4.x prior to 4.14.13 and is fixed upstream in 4.14.13; this project_version is 4.18.7. Patch application confirmed all patch commits already present in the target branch (c3f75107a4b4d00f802a56f23aa57cde134df838).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "Not affected: CVE-2025-46731 affects Craft CMS 4.x prior to 4.14.13 and is fixed upstream in 4.14.13; this project_version is 4.18.7. Patch application confirmed all patch commits already present in the target branch (c3f75107a4b4d00f802a56f23aa57cde134df838)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Not affected: CVE-2025-57811 affects Craft CMS 4.0.0-RC1 through 4.16.5 and is fixed upstream in 4.16.6; this project_version is 4.18.7. Patch application confirmed all patch commits already present in the target branch (e77f8a287dcdda41f1724f525d03542f18566cbc).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "Not affected: CVE-2025-57811 affects Craft CMS 4.0.0-RC1 through 4.16.5 and is fixed upstream in 4.16.6; this project_version is 4.18.7. Patch application confirmed all patch commits already present in the target branch (e77f8a287dcdda41f1724f525d03542f18566cbc)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-68436 fix 4bcb0db554e2 by brandon@pixelandtonic.com (2025-12-04) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-68436 fix 4bcb0db554e2 by brandon@pixelandtonic.com (2025-12-04) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-68437 fix 013db636fdb3 by brandon@pixelandtonic.com (2025-12-04) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68437"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-68437 fix 013db636fdb3 by brandon@pixelandtonic.com (2025-12-04) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Not affected: CVE-2025-68454 affects Craft CMS 4.0.0-RC1 through 4.16.16 and is fixed upstream in 4.16.17; this project_version is 4.18.7. Patch application confirmed all patch commits already present in the target branch (d82680f4a05f9576883bb83c3f6243d33ca73ebe).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "Not affected: CVE-2025-68454 affects Craft CMS 4.0.0-RC1 through 4.16.16 and is fixed upstream in 4.16.17; this project_version is 4.18.7. Patch application confirmed all patch commits already present in the target branch (d82680f4a05f9576883bb83c3f6243d33ca73ebe)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Version 4.18.7 is not affected by CVE-2025-68455. The vulnerability was fixed by upstream vendor (Craft CMS/Pixel & Tonic) in version 4.16.17 via commit ec43c497ed (released 2025-12-04). Target version 4.18.7 (released 2026-08-18) is newer and includes this fix plus additional hardening. The fix adds Component::cleanseConfig() to remove dangerous config keys (\"on \" event handlers and \"as \" behaviors) before object instantiation, preventing malicious behavior attachment and RCE. TuxCare later adopted version 4.18.7 into their ELS program, inheriting the upstream fix.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Version 4.18.7 is not affected by CVE-2025-68455. The vulnerability was fixed by upstream vendor (Craft CMS/Pixel & Tonic) in version 4.16.17 via commit ec43c497ed (released 2025-12-04). Target version 4.18.7 (released 2026-08-18) is newer and includes this fix plus additional hardening. The fix adds Component::cleanseConfig() to remove dangerous config keys (\"on \" event handlers and \"as \" behaviors) before object instantiation, preventing malicious behavior attachment and RCE. TuxCare later adopted version 4.18.7 into their ELS program, inheriting the upstream fix."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-68456 fix 1718011a5faa by brandon@pixelandtonic.com (2025-12-04) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68456"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2025-68456 fix 1718011a5faa by brandon@pixelandtonic.com (2025-12-04) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Version 4.18.7 is NOT AFFECTED by CVE-2026-25491. The vulnerability (stored XSS via unescaped entry type names) affects Craft CMS 5.0.0-RC1 through 5.8.21, where the architecture changed from Vue.js client-side rendering to PHP server-side rendering. In version 4.18.7, entry type names are rendered through Vue.js's default {{ }} interpolation (App.vue:115,120), which automatically applies HTML ...",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 4.18.7 is NOT AFFECTED by CVE-2026-25491. The vulnerability (stored XSS via unescaped entry type names) affects Craft CMS 5.0.0-RC1 through 5.8.21, where the architecture changed from Vue.js client-side rendering to PHP server-side rendering. In version 4.18.7, entry type names are rendered through Vue.js's default {{ }} interpolation (App.vue:115,120), which automatically applies HTML ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target (craftcms/cms 4.18.7) is NOT vulnerable to CVE-2026-25493. The upstream vendor fixed this SSRF redirect bypass vulnerability in commit 26268c0210 (June 2026), which was included in the 4.18.7 release (August 2026). The target code disables HTTP redirects at line 318 (`RequestOptions::ALLOW_REDIRECTS => false`) in the downloadUrl method, preventing attackers from bypassing validation ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 The target (craftcms/cms 4.18.7) is NOT vulnerable to CVE-2026-25493. The upstream vendor fixed this SSRF redirect bypass vulnerability in commit 26268c0210 (June 2026), which was included in the 4.18.7 release (August 2026). The target code disables HTTP redirects at line 318 (`RequestOptions::ALLOW_REDIRECTS => false`) in the downloadUrl method, preventing attackers from bypassing validation ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-25494 describes a hex IP notation bypass of filter_var() validation in the saveAsset GraphQL mutation. The target (4.18.7) is NOT AFFECTED because the vulnerable code pattern has been completely replaced by an upstream vendor refactoring. On June 15, 2026, upstream author brandon@pixelandtonic.com (commit 26268c0210) replaced the inline filter_var() validation with the craftcms/url-val...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25494 describes a hex IP notation bypass of filter_var() validation in the saveAsset GraphQL mutation. The target (4.18.7) is NOT AFFECTED because the vulnerable code pattern has been completely replaced by an upstream vendor refactoring. On June 15, 2026, upstream author brandon@pixelandtonic.com (commit 26268c0210) replaced the inline filter_var() validation with the craftcms/url-val..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Craft CMS 4.18.7 is not affected by CVE-2026-25495. The upstream vendor (Pixel & Tonic) fixed this SQL injection vulnerability in version 4.16.18 (released 2026-01-09) by removing dangerous SQL query construction parameters from user-provided criteria before database query configuration. The fix was refactored into ElementHelper::cleanseQueryCriteria() in version 4.17.4 (released 2026-02-11). The target version 4.18.7 (released 2026-08-18) inherits this upstream fix. The vulnerable pattern is not present in the target because an upstream-authored fix is already applied in the shipped version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "Craft CMS 4.18.7 is not affected by CVE-2026-25495. The upstream vendor (Pixel & Tonic) fixed this SQL injection vulnerability in version 4.16.18 (released 2026-01-09) by removing dangerous SQL query construction parameters from user-provided criteria before database query configuration. The fix was refactored into ElementHelper::cleanseQueryCriteria() in version 4.17.4 (released 2026-02-11). The target version 4.18.7 (released 2026-08-18) inherits this upstream fix. The vulnerable pattern is not present in the target because an upstream-authored fix is already applied in the shipped version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Target version 4.18.7 is not affected by CVE-2026-25496. The upstream vendor (Craft CMS / Pixel & Tonic) fixed the stored XSS vulnerability in commit 93837b626f on 2026-01-05 by adding HTML encoding to the Number field's Prefix and Suffix rendering. This fix was included in the upstream 4.18.7 release (finalized 2026-08-18), which TuxCare inherited when onboarding this version. The vulnerable p...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Target version 4.18.7 is not affected by CVE-2026-25496. The upstream vendor (Craft CMS / Pixel & Tonic) fixed the stored XSS vulnerability in commit 93837b626f on 2026-01-05 by adding HTML encoding to the Number field's Prefix and Suffix rendering. This fix was included in the upstream 4.18.7 release (finalized 2026-08-18), which TuxCare inherited when onboarding this version. The vulnerable p..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Target version 4.18.7 is not vulnerable to CVE-2026-25498. The upstream vendor (Pixel & Tonic) fixed the RCE vulnerability in commit 395c64f0b8 on 2026-01-09 by adding ComponentHelper::cleanseConfig() sanitization before passing user-supplied field layout configuration to object creation. This fix was included in the upstream 4.18.7 release (2026-08-18) which TuxCare subsequently onboarded for Extended Lifecycle Support. The vulnerable pattern (unsanitized config data passed directly to createLayout) is not present in the target.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "Target version 4.18.7 is not vulnerable to CVE-2026-25498. The upstream vendor (Pixel & Tonic) fixed the RCE vulnerability in commit 395c64f0b8 on 2026-01-09 by adding ComponentHelper::cleanseConfig() sanitization before passing user-supplied field layout configuration to object creation. This fix was included in the upstream 4.18.7 release (2026-08-18) which TuxCare subsequently onboarded for Extended Lifecycle Support. The vulnerable pattern (unsanitized config data passed directly to createLayout) is not present in the target."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Target version 4.18.7 is NOT AFFECTED. The vulnerability (CVE-2026-27126) affecting versions 4.5.0-RC1 through 4.16.18 was patched in upstream version 4.16.19. The target version 4.18.7 inherited the complete fix from upstream commit f5d488d9bb (authored by brandon@pixelandtonic.com on 2026-01-14). The fix validates table column types against a whitelist and converts unsupported types (includin...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Target version 4.18.7 is NOT AFFECTED. The vulnerability (CVE-2026-27126) affecting versions 4.5.0-RC1 through 4.16.18 was patched in upstream version 4.16.19. The target version 4.18.7 inherited the complete fix from upstream commit f5d488d9bb (authored by brandon@pixelandtonic.com on 2026-01-14). The fix validates table column types against a whitelist and converts unsupported types (includin..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. The target (craftcms/cms 4.18.7) is NOT vulnerable to CVE-2026-27127 (DNS rebinding TOCTOU SSRF). The upstream vendor (Pixel & Tonic) deployed a comprehensive fix in commit 26268c0210 (June 15, 2026) that implements DNS pinning via CURLOPT_RESOLVE and pre-validates IPs through the craftcms/url-validator package. This fix was naturally included in version 4.18.7 (released August 18, 2026). The vulnerable pattern (separate DNS lookups without pinning) has been completely removed from the codebase. This is a vendor-authored fix, not a TuxCare backport.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27127"
      },
      "impact_statement": "The target (craftcms/cms 4.18.7) is NOT vulnerable to CVE-2026-27127 (DNS rebinding TOCTOU SSRF). The upstream vendor (Pixel & Tonic) deployed a comprehensive fix in commit 26268c0210 (June 15, 2026) that implements DNS pinning via CURLOPT_RESOLVE and pre-validates IPs through the craftcms/url-validator package. This fix was naturally included in version 4.18.7 (released August 18, 2026). The vulnerable pattern (separate DNS lookups without pinning) has been completely removed from the codebase. This is a vendor-authored fix, not a TuxCare backport."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository at version 4.18.7 is NOT vulnerable to CVE-2026-27128. The TOCTOU race condition fix was applied by the upstream vendor (Pixel & Tonic) in commit 3e4afe1827 as part of version 4.16.19 (released 2026-01-15). Version 4.18.7, being newer than 4.16.19, naturally includes this fix. The getTokenRoute() method in src/services/Tokens.php correctly uses mutex locking to ensure atom...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository at version 4.18.7 is NOT vulnerable to CVE-2026-27128. The TOCTOU race condition fix was applied by the upstream vendor (Pixel & Tonic) in commit 3e4afe1827 as part of version 4.16.19 (released 2026-01-15). Version 4.18.7, being newer than 4.16.19, naturally includes this fix. The getTokenRoute() method in src/services/Tokens.php correctly uses mutex locking to ensure atom..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target (Craft CMS 4.18.7) is NOT AFFECTED by CVE-2026-27129. The vulnerable pattern (using gethostbyname() which only resolves IPv4) is absent because the upstream vendor refactored the code to use the craftcms/url-validator library (commit 26268c0210, Jun 2026). This library uses dns_get_record() with both DNS_A and DNS_AAAA records, and includes comprehensive IPv6 validation via FILTER_FL...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "impact_statement": "not_affected \u2014 The target (Craft CMS 4.18.7) is NOT AFFECTED by CVE-2026-27129. The vulnerable pattern (using gethostbyname() which only resolves IPv4) is absent because the upstream vendor refactored the code to use the craftcms/url-validator library (commit 26268c0210, Jun 2026). This library uses dns_get_record() with both DNS_A and DNS_AAAA records, and includes comprehensive IPv6 validation via FILTER_FL..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. The target craftcms/cms 4.18.7 contains the upstream vendor fix for CVE-2026-31857. The vulnerable unsandboxed Twig rendering call has been replaced with the sandboxed version in BaseElementSelectConditionRule.php line 88. Fix commit 8d4903647d was authored by brandon@pixelandtonic.com (Craft CMS upstream vendor) as part of the 4.17.4 release, and is included in the 4.18.7 version onboarded by TuxCare.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "The target craftcms/cms 4.18.7 contains the upstream vendor fix for CVE-2026-31857. The vulnerable unsandboxed Twig rendering call has been replaced with the sandboxed version in BaseElementSelectConditionRule.php line 88. Fix commit 8d4903647d was authored by brandon@pixelandtonic.com (Craft CMS upstream vendor) as part of the 4.17.4 release, and is included in the 4.18.7 version onboarded by TuxCare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. CVE-2026-31858 does not affect Craft CMS version 4.18.7. The vulnerable component ElementSearchController was introduced in Craft CMS 5.x and does not exist in version 4.x. The target repository is running version 4.18.7, which predates the introduction of this controller. The only controller in version 4.18.7 that processes user query criteria (ElementIndexesController) already contains the proper defense mechanism (ElementHelper::cleanseQueryCriteria()) that was added for CVE-2026-25495. No alternative code path exists in version 4.18.7 that exhibits the same SQL injection vulnerability pattern.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "CVE-2026-31858 does not affect Craft CMS version 4.18.7. The vulnerable component ElementSearchController was introduced in Craft CMS 5.x and does not exist in version 4.x. The target repository is running version 4.18.7, which predates the introduction of this controller. The only controller in version 4.18.7 that processes user query criteria (ElementIndexesController) already contains the proper defense mechanism (ElementHelper::cleanseQueryCriteria()) that was added for CVE-2026-25495. No alternative code path exists in version 4.18.7 that exhibits the same SQL injection vulnerability pattern."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Target version 4.18.7 is NOT AFFECTED. The vulnerability (XSS via javascript: URLs bypassing strip_tags()) was fixed by upstream vendor commit cc9921c14897ee2b592a431c2356af8a04ce4cfe, which added URL scheme validation before strip_tags() in src/web/User.php::setReturnUrl(). This fix was already present in upstream version 4.18.7 (released 2026-08-18) when TuxCare onboarded it (commit 4a22c9d3d...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "impact_statement": "not_affected \u2014 Target version 4.18.7 is NOT AFFECTED. The vulnerability (XSS via javascript: URLs bypassing strip_tags()) was fixed by upstream vendor commit cc9921c14897ee2b592a431c2356af8a04ce4cfe, which added URL scheme validation before strip_tags() in src/web/User.php::setReturnUrl(). This fix was already present in upstream version 4.18.7 (released 2026-08-18) when TuxCare onboarded it (commit 4a22c9d3d..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target (craftcms/cms 4.18.7) is not affected by CVE-2026-32262. The vulnerability (path traversal via unsanitized targetFilename parameter in AssetsController->replaceFile() allowing arbitrary file deletion) was fixed by upstream vendor Pixel & Tonic in version 4.17.5 (commit c997efbe4c, Feb 16 2026). The target version 4.18.7 inherits this fix from upstream. The validation code rejecting f...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The target (craftcms/cms 4.18.7) is not affected by CVE-2026-32262. The vulnerability (path traversal via unsanitized targetFilename parameter in AssetsController->replaceFile() allowing arbitrary file deletion) was fixed by upstream vendor Pixel & Tonic in version 4.17.5 (commit c997efbe4c, Feb 16 2026). The target version 4.18.7 inherits this fix from upstream. The validation code rejecting f..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. CVE-2026-32263 affects Craft CMS versions 5.6.0 to before 5.9.11, specifically in src/controllers/EntryTypesController.php. The target version 4.18.7 is not affected because: (1) EntryTypesController.php does not exist in version 4.x; (2) Entry type management in 4.x is handled by SectionsController.php which does not use parse_str; (3) All 4 instances of parse_str in version 4.18.7 controllers (FieldsController.php and ElementIndexesController.php) are protected with Component::cleanseConfig() before passing data to Craft::configure(). The vulnerable code pattern described in the CVE does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 affects Craft CMS versions 5.6.0 to before 5.9.11, specifically in src/controllers/EntryTypesController.php. The target version 4.18.7 is not affected because: (1) EntryTypesController.php does not exist in version 4.x; (2) Entry type management in 4.x is handled by SectionsController.php which does not use parse_str; (3) All 4 instances of parse_str in version 4.18.7 controllers (FieldsController.php and ElementIndexesController.php) are protected with Component::cleanseConfig() before passing data to Craft::configure(). The vulnerable code pattern described in the CVE does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-32264 fix dfec46362fcb by brandon@pixelandtonic.com (2026-02-16) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-32264 fix dfec46362fcb by brandon@pixelandtonic.com (2026-02-16) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-32267 fix 6301e217c5f1 by brandon@pixelandtonic.com (2026-02-18) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-32267 fix 6301e217c5f1 by brandon@pixelandtonic.com (2026-02-18) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 4.18.7 is not affected by CVE-2026-33051. The CVE describes an XSS vulnerability specific to versions 5.9.0-beta.1 through 5.9.10 where the creator's fullName is rendered as raw HTML due to Template::raw() combined with Craft::t() in the revision/draft context menu. While the target version 4.18.7 does display creator names in the revision menu (src/templates/_includes/revisionmenu.tw...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 4.18.7 is not affected by CVE-2026-33051. The CVE describes an XSS vulnerability specific to versions 5.9.0-beta.1 through 5.9.10 where the creator's fullName is rendered as raw HTML due to Template::raw() combined with Craft::t() in the revision/draft context menu. While the target version 4.18.7 does display creator names in the revision menu (src/templates/_includes/revisionmenu.tw..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Version 4.18.7 is NOT affected by CVE-2026-33157. The vulnerability exists in Craft CMS 5.6.0-5.9.12 where a NEW code path (fieldLayouts parameter in ElementIndexesController::actionFilterHud) bypasses existing sanitization. This specific code path does NOT exist in version 4.x. Version 4.18.7 only processes conditionConfig in actionFilterHud(), which is properly sanitized via Component::cleanseConfig() at line 421. The setFieldLayouts() method and fieldLayouts parameter handling were introduced in version 5.x and are completely absent from version 4.18.7's codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "Version 4.18.7 is NOT affected by CVE-2026-33157. The vulnerability exists in Craft CMS 5.6.0-5.9.12 where a NEW code path (fieldLayouts parameter in ElementIndexesController::actionFilterHud) bypasses existing sanitization. This specific code path does NOT exist in version 4.x. Version 4.18.7 only processes conditionConfig in actionFilterHud(), which is properly sanitized via Component::cleanseConfig() at line 421. The setFieldLayouts() method and fieldLayouts parameter handling were introduced in version 5.x and are completely absent from version 4.18.7's codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-33158 is NOT present in Craft CMS 4.18.7. The vulnerability described an authorization bypass in the assets/edit-image endpoint allowing low-privileged users to read private asset content. The upstream vendor (Pixel & Tonic) fixed this in version 4.17.8 (commit e674bbbd30, Feb 25 2026) by adding requireVolumePermissionByAsset() and requirePeerVolumePermissionByAsset() checks. Version 4...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33158 is NOT present in Craft CMS 4.18.7. The vulnerability described an authorization bypass in the assets/edit-image endpoint allowing low-privileged users to read private asset content. The upstream vendor (Pixel & Tonic) fixed this in version 4.17.8 (commit e674bbbd30, Feb 25 2026) by adding requireVolumePermissionByAsset() and requirePeerVolumePermissionByAsset() checks. Version 4..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target (Craft CMS 4.18.7) contains the complete fix for CVE-2026-33159. The upstream vendor (Pixel & Tonic) fixed the vulnerability in commit 7f0ead833f (2026-02-25), included it in their 4.18.7 release (2026-08-18), and TuxCare onboarded that pre-fixed version (2026-09-07). The vulnerable pattern\u2014missing authentication/authorization on ConfigSyncController\u2014is not present at HEAD. Verdict: ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 The target (Craft CMS 4.18.7) contains the complete fix for CVE-2026-33159. The upstream vendor (Pixel & Tonic) fixed the vulnerability in commit 7f0ead833f (2026-02-25), included it in their 4.18.7 release (2026-08-18), and TuxCare onboarded that pre-fixed version (2026-09-07). The vulnerable pattern\u2014missing authentication/authorization on ConfigSyncController\u2014is not present at HEAD. Verdict: ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-33160 fix 83fd398c12a3 by brandon@pixelandtonic.com (2026-02-25) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-33160 fix 83fd398c12a3 by brandon@pixelandtonic.com (2026-02-25) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 4.18.7) contains the upstream vendor's fix for the asset information disclosure vulnerability. The CVE describes an authorization bypass where the assets/image-editor endpoint (actionImageEditor method) returns focalPoint and other editor metadata without validating user permissions. The fix (commit 1f91f9b7aa, GHSA-vgjg-248p-rfm2) added requireVolumePermissionB...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 4.18.7) contains the upstream vendor's fix for the asset information disclosure vulnerability. The CVE describes an authorization bypass where the assets/image-editor endpoint (actionImageEditor method) returns focalPoint and other editor metadata without validating user permissions. The fix (commit 1f91f9b7aa, GHSA-vgjg-248p-rfm2) added requireVolumePermissionB..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS v4.18.7 is not affected by CVE-2026-33162. The vulnerability affects the `/actions/entries/move-to-section` endpoint and Entry::canMove() authorization method, which were introduced in Craft CMS v5.x. Version 4.18.7 does not have the move-entries-between-sections feature at all. The GraphQL resolver explicitly prevents section changes with the error \"Impossible to change the section o...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 Craft CMS v4.18.7 is not affected by CVE-2026-33162. The vulnerability affects the `/actions/entries/move-to-section` endpoint and Entry::canMove() authorization method, which were introduced in Craft CMS v5.x. Version 4.18.7 does not have the move-entries-between-sections feature at all. The GraphQL resolver explicitly prevents section changes with the error \"Impossible to change the section o..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-41129 (SSRF via unvalidated URL scheme in GraphQL asset upload) is NOT present in target version 4.18.7. The upstream vendor (Pixel & Tonic) fixed this vulnerability in commit d20aecfaa0 (March 4, 2026) by adding scheme validation that blocks non-HTTP/HTTPS protocols (gopher, file, ftp, etc.). This fix was later refactored into the craftcms/url-validator library (commit 26268c0210, Jun...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-41129 (SSRF via unvalidated URL scheme in GraphQL asset upload) is NOT present in target version 4.18.7. The upstream vendor (Pixel & Tonic) fixed this vulnerability in commit d20aecfaa0 (March 4, 2026) by adding scheme validation that blocks non-HTTP/HTTPS protocols (gopher, file, ftp, etc.). This fix was later refactored into the craftcms/url-validator library (commit 26268c0210, Jun..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 The target (Craft CMS 4.18.7) is not affected by CVE-2026-41130. The SSRF vulnerability in the resource-js endpoint was fixed by upstream vendor (Pixel & Tonic) in commit ebe7e85f1c, which is present in the target. The vulnerable code that made HTTP requests via Guzzle client has been replaced with local filesystem serving using App::resourcePathByUri() with path traversal protection. Additiona...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target (Craft CMS 4.18.7) is not affected by CVE-2026-41130. The SSRF vulnerability in the resource-js endpoint was fixed by upstream vendor (Pixel & Tonic) in commit ebe7e85f1c, which is present in the target. The vulnerable code that made HTTP requests via Guzzle client has been replaced with local filesystem serving using App::resourcePathByUri() with path traversal protection. Additiona..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. CVE-2026-55790 (GHSA-24x4-j6x9-rfw5): The XSS vulnerability in the CraftSupport widget is NOT present in target version 4.18.7. The upstream vendor (Pixel & Tonic) fixed this vulnerability in commit 6bbb66038a (May 2026) by adding HTML escaping via Craft.escapeHtml() and using jQuery's text: option for error messages. This fix was included in upstream's 4.18.7 release (August 2026), which TuxCare subsequently adopted for ELS support (September 2026). TuxCare did not backport this specific fix; they inherited an already-fixed upstream release. Both defense mechanisms from the patch are present and correctly implemented at lines 382 and 555-557 of CraftSupportWidget.js.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55790"
      },
      "impact_statement": "CVE-2026-55790 (GHSA-24x4-j6x9-rfw5): The XSS vulnerability in the CraftSupport widget is NOT present in target version 4.18.7. The upstream vendor (Pixel & Tonic) fixed this vulnerability in commit 6bbb66038a (May 2026) by adding HTML escaping via Craft.escapeHtml() and using jQuery's text: option for error messages. This fix was included in upstream's 4.18.7 release (August 2026), which TuxCare subsequently adopted for ELS support (September 2026). TuxCare did not backport this specific fix; they inherited an already-fixed upstream release. Both defense mechanisms from the patch are present and correctly implemented at lines 382 and 555-557 of CraftSupportWidget.js."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 is fixed in version 4.18.7-p1+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-55793"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Target version 4.18.7 is not affected. The CVE describes a vulnerability in version 5.0.0-RC1+, but analysis of 4.18.7 code shows user group names are protected by Twig's default HTML auto-escaping and Vue's text interpolation escaping. All rendering paths include runtime defenses that transform script content before display, preventing execution in administrators' browsers.",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Target version 4.18.7 is not affected. The CVE describes a vulnerability in version 5.0.0-RC1+, but analysis of 4.18.7 code shows user group names are protected by Twig's default HTML auto-escaping and Vue's text interpolation escaping. All rendering paths include runtime defenses that transform script content before display, preventing execution in administrators' browsers."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Target version 4.18.7 is not affected by CVE-2026-56382. The vulnerable method `actionRenderCardPreview()` from the v5.x patch does not exist in v4.18.7's codebase. The CVE affects Craft CMS versions >= 5.5.0 and <= 5.9.13, while this target is v4.18.7. Although TuxCare backported this CVE to v3.9.15 (fixing a different vulnerable method `actionRenderLayoutElementSelector()`), v4.18.7 contains neither the v5.x vulnerable method nor the v3.x vulnerable method. The methods that do exist in v4.18.7 and handle layout configurations (`actionApplyLayoutTabSettings()`, `actionApplyLayoutElementSettings()`) properly sanitize all config parameters via `Component::cleanseConfig()` before passing them to layout creation functions.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "impact_statement": "Target version 4.18.7 is not affected by CVE-2026-56382. The vulnerable method `actionRenderCardPreview()` from the v5.x patch does not exist in v4.18.7's codebase. The CVE affects Craft CMS versions >= 5.5.0 and <= 5.9.13, while this target is v4.18.7. Although TuxCare backported this CVE to v3.9.15 (fixing a different vulnerable method `actionRenderLayoutElementSelector()`), v4.18.7 contains neither the v5.x vulnerable method nor the v3.x vulnerable method. The methods that do exist in v4.18.7 and handle layout configurations (`actionApplyLayoutTabSettings()`, `actionApplyLayoutElementSettings()`) properly sanitize all config parameters via `Component::cleanseConfig()` before passing them to layout creation functions."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Target version 4.18.7 is NOT AFFECTED. The upstream vendor fix (commit 7b372de262b8) is present in HEAD, applying HTML encoding to heading-type cell values before rendering. The fix was authored by brandon@pixelandtonic.com (Craft CMS upstream) and shipped in version 4.16.19. TuxCare onboarded version 4.18.7 (released 2026-08-18) which already contained this fix. No TuxCare attribution signals ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "impact_statement": "not_affected \u2014 Target version 4.18.7 is NOT AFFECTED. The upstream vendor fix (commit 7b372de262b8) is present in HEAD, applying HTML encoding to heading-type cell values before rendering. The fix was authored by brandon@pixelandtonic.com (Craft CMS upstream) and shipped in version 4.16.19. TuxCare onboarded version 4.18.7 (released 2026-08-18) which already contained this fix. No TuxCare attribution signals ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-56384 fix ed56049c9d3f by brandon@pixelandtonic.com (2026-02-25) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56384"
      },
      "impact_statement": "not_affected \u2014 fixed upstream before 4.18.7: CVE-2026-56384 fix ed56049c9d3f by brandon@pixelandtonic.com (2026-02-25) is an ancestor of tuxcare-current/4.18.7; no TuxCare backport for this CVE on the branch \u2014 the CloudLinux commit VC credited is the onboarding merge (bashebr@cloudlinux.com, 2026-09-07). Manual re-label of VC verdict already_fixed\u2192not_affected after git verification, 2026-09-11."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. not_affected \u2014 Target version 4.18.7 contains the upstream vendor's authorization fix for CVE-2026-56385. The vulnerability (authorization bypass in assets/preview-file endpoint) was fixed by Pixel & Tonic in commit d30df31122 (Feb 2026) which added requireVolumePermissionByAsset and requirePeerVolumePermissionByAsset checks to actionPreviewFile(). This fix was included in upstream Craft CMS 4.17.8 and 4.18.7...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "impact_statement": "not_affected \u2014 Target version 4.18.7 contains the upstream vendor's authorization fix for CVE-2026-56385. The vulnerability (authorization bypass in assets/preview-file endpoint) was fixed by Pixel & Tonic in commit d30df31122 (Feb 2026) which added requireVolumePermissionByAsset and requirePeerVolumePermissionByAsset checks to actionPreviewFile(). This fix was included in upstream Craft CMS 4.17.8 and 4.18.7..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@4.18.7-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 4.18.7-p1+tuxcare of craftcms/cms. Target Craft CMS 4.18.7 is not affected by CVE-2026-56394 (GHSA-472v-j2g4-g9h2). The path traversal vulnerability in the assets/icon endpoint has been fixed by upstream vendor commit 30f5f1a8d6 (authored by brandon@pixelandtonic.com), which added regex validation to reject extension parameters containing traversal sequences. The fix validates extensions with /^\\w+$/ before filesystem operations, preventing the attack chain described in the CVE. TuxCare adopted this fix when onboarding version 4.18.7 to ELS support.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "Target Craft CMS 4.18.7 is not affected by CVE-2026-56394 (GHSA-472v-j2g4-g9h2). The path traversal vulnerability in the assets/icon endpoint has been fixed by upstream vendor commit 30f5f1a8d6 (authored by brandon@pixelandtonic.com), which added regex validation to reject extension parameters containing traversal sequences. The fix validates extensions with /^\\w+$/ before filesystem operations, preventing the attack chain described in the CVE. TuxCare adopted this fix when onboarding version 4.18.7 to ELS support."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p9+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p9+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p9+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p9+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p9+tuxcare of craftcms/cms."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p9+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p9+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2018-1000162 is fixed in version 1.6.4-p1+tuxcare of erusev/parsedown.",
      "vulnerability": {
        "name": "CVE-2018-1000162"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/erusev/parsedown@1.6.4-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T14:43:41.647513+00:00",
      "status_notes": "Vulnerability CVE-2019-10905 does not affect version 1.6.4-p1+tuxcare of erusev/parsedown. Version 1.6.x is NOT affected by CVE-2019-10905. The vulnerability exists only in versions 1.7.0\u20131.7.1 which used a permissive regex pattern ([^`]+)? that captures spaces in code fence infostrings. Version 1.6.x uses the restrictive pattern ([\\w-]+)? that rejects lines with spaces, preventing the attack chain from completing. The regex at line 399 fails to match infostrings like \"javascript extra\", so no code block is created and no class injection occurs. Python regex testing confirms this behavior. The patch commit message \"[1.7.x] Fix spaces in class names\" indicates the fix targets the 1.7.x branch specifically.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2019-10905"
      },
      "impact_statement": "Version 1.6.x is NOT affected by CVE-2019-10905. The vulnerability exists only in versions 1.7.0\u20131.7.1 which used a permissive regex pattern ([^`]+)? that captures spaces in code fence infostrings. Version 1.6.x uses the restrictive pattern ([\\w-]+)? that rejects lines with spaces, preventing the attack chain from completing. The regex at line 399 fails to match infostrings like \"javascript extra\", so no code block is created and no class injection occurs. Python regex testing confirms this behavior. The patch commit message \"[1.7.x] Fix spaces in class names\" indicates the fix targets the 1.7.x branch specifically."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 affects version 6.5.8-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      },
      "action_statement": "Vulnerability CVE-2026-69245 affects version 6.5.8-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 affects version 6.5.8-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      },
      "action_statement": "Vulnerability CVE-2026-69246 affects version 6.5.8-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.5.8-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      },
      "action_statement": "Vulnerability GHSA-f283-ghqc-fg79 affects version 6.5.8-p2+tuxcare of guzzlehttp/guzzle, and is fixed in 6.5.8-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 6.5.8-p2+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.5.8-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 6.5.8-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-12393"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-45440"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55634"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55636"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55637"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2024-55638"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-13080"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13081 affects version 9.5.11-p5+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13081"
      },
      "action_statement": "Vulnerability CVE-2025-13081 affects version 9.5.11-p5+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13082 affects version 9.5.11-p5+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13082"
      },
      "action_statement": "Vulnerability CVE-2025-13082 affects version 9.5.11-p5+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-13083 affects version 9.5.11-p5+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-13083"
      },
      "action_statement": "Vulnerability CVE-2025-13083 affects version 9.5.11-p5+tuxcare of drupal/core, and is fixed in 9.5.11-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-3057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31673"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31674"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2025-31675"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6365"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-6366"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "CVE-2026-9082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p5+tuxcare of drupal/core.",
      "vulnerability": {
        "name": "GHSA-6CCV-8FGF-CJPW"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p5+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-6ccv-8fgf-cjpw"
      },
      "impact_statement": "already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "CVE-2022-37251 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "CVE-2023-31144 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "CVE-2023-33195 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "CVE-2023-33196 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "CVE-2023-33197 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "CVE-2023-40035 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "CVE-2023-41892 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match.",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "false_positive \u2014 CVE-2024-21622 targets Craft CMS core (craftcms/cms), but this repository contains verbb/feed-me, a Craft CMS plugin. The affected component code (Craft CMS core) is absent from this repository. This is a wrong-project match."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "CVE-2024-41800 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "CVE-2024-52293 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "CVE-2025-23209 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products.",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "false_positive \u2014 CVE-2025-32432 concerns Craft CMS core (craftcms/cms) versions 3.0.0-RC1 to before 3.9.15. The target repository is Feed Me plugin (verbb/feed-me) version 3.1.17, a different product with independent versioning. This is a wrong-project match caused by version number collision between two separate products."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab...",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-46731 affects Craft CMS core versions 4.x (prior to 4.14.13) and 5.x (prior to 5.6.16). The target repository is the Feed Me plugin (verbb/feed-me) version 3.1.17, which depends on Craft CMS 3.x. The CVE does not mention Craft CMS 3.x as affected. While the plugin does use Twig template rendering via Craft CMS's renderObjectTemplate API with administrator-controlled input, the vulnerab..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th...",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-57811. While the plugin does pass user-controlled feed data to Craft's renderObjectTemplate() method when parseTwig is enabled, the vulnerability only exists in Craft CMS versions 4.x and 5.x. Feed Me v3.1.17 is constrained to run exclusively on Craft CMS 3.x (per composer.json requirement: 'craftcms/cms': '^3.1.0'), which is not affected by th..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2025-68436. This vulnerability affects Craft CMS core versions 4.x and 5.x user profile photo functionality, while Feed Me is a plugin for Craft CMS 3.x that does not implement user profile photo management features. Feed Me only provides admin-only bulk import functionality for user data from feeds, which is architecturally different from the indiv..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2025-68454. The vulnerability targets Craft CMS core features (Settings text fields and System Messages utility) that do not exist in the Feed Me plugin codebase. Feed Me's Twig processing serves a different purpose (processing external feed data) and does not expose the vulnerable attack vector described in the CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "not_affected \u2014 CVE-2025-68455 affects Craft CMS core's Behavior attachment functionality in versions 4.x and 5.x. The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that handles feed imports. Exhaustive analysis confirms the plugin does not implement, use, or interact with Craft's Behavior system. The vulnerability pattern (malicious Behavior attachment leading to RCE) does not apply b..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "CVE-2026-25491 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25493"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-25493 targets the saveAsset GraphQL mutation in Craft CMS core versions 4.x and 5.x. This repository is verbb/feed-me v3.1.17, a plugin for Craft CMS 3.x that does not implement or use the vulnerable GraphQL mutation. The specific vulnerable component does not exist in this project."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron...",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-25494 concerns Craft CMS core (craftcms/cms versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.22), specifically the saveAsset GraphQL mutation. This repository is verbb/feed-me version 3.1.17-p1+tuxcare, a plugin FOR Craft CMS, not Craft CMS itself. The affected component (saveAsset GraphQL mutation with IP validation) does not exist in this plugin's codebase. This is a wron..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25495"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17, a Craft CMS plugin) is not affected by CVE-2026-25495. The vulnerability exists in Craft CMS core's element-indexes/get-elements endpoint which processes criteria[orderBy] parameters. This endpoint does not exist in the plugin. While the plugin contains a getFeeds($orderBy) method with a similar unsanitized pattern, it is never exposed to user input..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin is not affected by CVE-2026-25496. The vulnerability concerns Craft CMS core's Number field type settings rendering (Prefix/Suffix with |md|raw filter), but Feed Me is a data import plugin that does not implement field settings UI, field rendering, or handle Number field Prefix/Suffix configuration. Feed Me only maps imported data values to existing Craft fields and never process..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "impact_statement": "not_affected \u2014 The feed-me plugin v3.1.17 is not affected by CVE-2026-25498. The vulnerability exists in Craft CMS core (v4.0.0-RC1+ and v5.0.0-RC1+) in the assembleLayoutFromPost() function which does not exist in this plugin. While feed-me uses similar object creation functions (ComponentHelper::createComponent), these are only called with hardcoded class names from internal registries, never with user-cont..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin v3.1.17 is not affected by CVE-2026-27126. The vulnerability exists in Craft CMS core's editableTable.twig component (versions 4.5.0+ and 5.0.0+), which Feed Me does not use, implement, or interact with. Feed Me is a data import plugin that operates at a different architectural layer than the vulnerable admin UI rendering component."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27128"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin for importing content from feeds. The CVE-2026-27128 vulnerability exists in Craft CMS core's token validation service (specifically the getTokenRoute() method's TOCTOU race condition). After exhaustive analysis, the plugin's codebase does not implement, use, or interact with Craft CMS's token validation service or impersonatio..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n...",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "impact_statement": "not_affected \u2014 Feed Me plugin (verbb/feed-me v3.1.17) is not affected by CVE-2026-29113. The vulnerability exists in Craft CMS core's preview token endpoint (/actions/preview/create-token), which is part of the craftcms/cms package. This plugin does not implement, interact with, or depend on the vulnerable preview token creation functionality. The plugin's codebase focuses on feed import operations and does n..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t...",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31857 targets Craft CMS core's BaseElementSelectConditionRule class in versions 4.x and 5.x. The target repository is verbb/feed-me plugin v3.1.17, which depends on Craft CMS 3.1.5. The vulnerable conditions system and BaseElementSelectConditionRule class were introduced in Craft CMS 4.0 and do not exist in version 3.x. The plugin does not implement or use condition rules. Therefore, t..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core...",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in Craft CMS core's ElementSearchController::actionSearch() endpoint. The target repository (verbb/feed-me v3.1.17) is a Craft CMS plugin, not Craft CMS core itself. The vulnerable endpoint and controller classes (ElementSearchController, ElementIndexesController) do not exist in this plugin's codebase. The vulnerability resides in the core..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "impact_statement": "not_affected \u2014 The CVE-2026-32262 vulnerability exists in Craft CMS core's AssetsController->replaceFile() method. This repository is verbb/feed-me version 3.1.17, a Craft CMS plugin, not the CMS core itself. The plugin does not implement the vulnerable endpoint or replicate the vulnerable pattern. While the plugin processes filenames from feeds, all filenames are sanitized via AssetsHelper::prepareAssetName(..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "CVE-2026-32263 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra...",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me v3.1.17, a plugin for Craft CMS. CVE-2026-32264 describes a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController, which are core Craft CMS controllers in the craftcms/cms package (versions 4.x and 5.x). This plugin does not contain these controllers, does not implement behavior injection patterns, and its dependency constra..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32267"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32267 concerns Craft CMS core's UsersController->actionImpersonateWithToken privilege escalation vulnerability. The target repository is verbb/feed-me version 3.1.17, a Craft CMS plugin (not the CMS core itself). The plugin provides feed import functionality and does not contain the affected component (UsersController), does not implement any user impersonation functionality, and does ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "CVE-2026-33051 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil...",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-33157 affects Craft CMS core (versions 5.6.0 to 5.9.13), specifically ElementIndexesController::actionFilterHud() and FieldLayout::createFromConfig(). The target repository is verbb/feed-me 3.1.17, a Craft CMS plugin that requires craftcms/cms ^3.1.0. The plugin does not contain, invoke, or interact with the vulnerable Craft CMS core components. Type A1 analysis confirms the vulnerabil..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me plugin v3.1.17) is not affected by CVE-2026-33158. The vulnerability exists in Craft CMS core's assets/edit-image endpoint, which is not implemented by this plugin. The plugin's asset functionality is limited to importing assets from feeds and does not include any asset viewing or editing endpoints that could exhibit the authorization bypass vulnerability."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "impact_statement": "not_affected \u2014 Target repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS core. CVE-2026-33159 concerns Craft CMS's Config Sync feature authentication bypass. This plugin does not implement, extend, or interact with Config Sync functionality."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me (version 3.1.17), a Craft CMS plugin for importing content from feeds. CVE-2026-33160 concerns a vulnerability in Craft CMS core's assets/generate-transform endpoint. This plugin does not implement, extend, or interact with asset transformation functionality. The vulnerable code path exists only in Craft CMS core, not in this plugin repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is a false positive for verbb/feed-me 3.1.17-p2+tuxcare. false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "impact_statement": "false_positive \u2014 CVE-2026-33161 is a false positive for this repository. The vulnerability concerns Craft CMS core's assets/image-editor endpoint, but this repository is verbb/feed-me (a Craft CMS plugin), not Craft CMS itself. The vulnerable code does not exist in this codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do...",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "not_affected \u2014 The target repository (verbb/feed-me v3.1.17) is a plugin for Craft CMS that provides feed import functionality. The vulnerability CVE-2026-33162 affects the core Craft CMS product (craftcms/cms v5.3.0-5.9.13), specifically the /actions/entries/move-to-section endpoint in the EntriesController. This plugin does not implement, vendor, or bundle this vulnerable component. The plugin's own code do..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details.",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 in craftcms/cms 3.9.15 is not affected. Refer to craftcms/cms 3.9.15 for details."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/verbb/feed-me@3.1.17-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.1.17-p2+tuxcare of verbb/feed-me. not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 The target repository is verbb/feed-me version 3.1.17, a plugin for Craft CMS, not Craft CMS core itself. CVE-2026-41130 affects the resource-js endpoint in Craft CMS core versions 4.x through 4.17.8 and 5.x through 5.9.14. This plugin targets Craft CMS 3.x (^3.1.0) and does not implement the vulnerable resource-js endpoint or any similar functionality that proxies JavaScript resources based on..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laminas/laminas-diactoros@2.22.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laminas/laminas-diactoros@2.22.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29530 is fixed in version 2.22.0-p1+tuxcare of laminas/laminas-diactoros.",
      "vulnerability": {
        "name": "CVE-2023-29530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29248 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-29248"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31042 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31042"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31043 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31043"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31090 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31091 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2022-31091"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@6.0.2-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 6.0.2-p5+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7809 does not affect version v2.15.6-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is running Twig 2.15.6, which is significantly newer than the vulnerable versions. The security fix that prevents arbitrary code execution via the _self variable in Sandbox mode is present in the target code at src/Template.php lines 175-178, with explicit documentation ('avoid RCEs when sandbox is enabled') and test coverage.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2015-7809"
      },
      "impact_statement": "already_fixed \u2014 CVE-2015-7809 affects Twig before version 1.20.0. The target repository is running Twig 2.15.6, which is significantly newer than the vulnerable versions. The security fix that prevents arbitrary code execution via the _self variable in Sandbox mode is present in the target code at src/Template.php lines 175-178, with explicit documentation ('avoid RCEs when sandbox is enabled') and test coverage."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-9942 does not affect version v2.15.6-p1+tuxcare of twig/twig. already_fixed \u2014 CVE-2019-9942 was fixed in Twig version 2.7.0 (released 2019-03-12). The target version 2.15.6 (released 2023-11-21) already contains the complete fix. The vulnerability allowed calling __toString() on objects in sandbox mode even when not allowed by the security policy. The fix introduces ensureToStringAllowed() method and CheckToStringNode wrapping mechanism that validates all implicit __toSt...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2019-9942"
      },
      "impact_statement": "already_fixed \u2014 CVE-2019-9942 was fixed in Twig version 2.7.0 (released 2019-03-12). The target version 2.15.6 (released 2023-11-21) already contains the complete fix. The vulnerability allowed calling __toString() on objects in sandbox mode even when not allowed by the security policy. The fix introduces ensureToStringAllowed() method and CheckToStringNode wrapping mechanism that validates all implicit __toSt..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-45411 is fixed in version v2.15.6-p1+tuxcare of twig/twig.",
      "vulnerability": {
        "name": "CVE-2024-45411"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51754 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-51754"
      },
      "action_statement": "Vulnerability CVE-2024-51754 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51755 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-51755"
      },
      "action_statement": "Vulnerability CVE-2024-51755 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46628 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-46628"
      },
      "action_statement": "Vulnerability CVE-2026-46628 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46633 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-46633"
      },
      "action_statement": "Vulnerability CVE-2026-46633 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46635 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-46635"
      },
      "action_statement": "Vulnerability CVE-2026-46635 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46638 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-46638"
      },
      "action_statement": "Vulnerability CVE-2026-46638 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47732 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-47732"
      },
      "action_statement": "Vulnerability CVE-2026-47732 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48805 does not affect version v2.15.6-p1+tuxcare of twig/twig. not_affected \u2014 Twig v2.15.6 is not affected by CVE-2026-48805. The vulnerability exists only in Twig 3.26.0+ where architectural changes introduced deprecated wrapper functions in src/Resources/core.php that fail to forward sandbox state to CoreExtension methods. This architectural pattern does not exist in v2.15.6, which uses a different implementation where sandbox enforcement is correctly handled.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48805"
      },
      "impact_statement": "not_affected \u2014 Twig v2.15.6 is not affected by CVE-2026-48805. The vulnerability exists only in Twig 3.26.0+ where architectural changes introduced deprecated wrapper functions in src/Resources/core.php that fail to forward sandbox state to CoreExtension methods. This architectural pattern does not exist in v2.15.6, which uses a different implementation where sandbox enforcement is correctly handled."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48806 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48806"
      },
      "action_statement": "Vulnerability CVE-2026-48806 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48807 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48807"
      },
      "action_statement": "Vulnerability CVE-2026-48807 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48808 does not affect version v2.15.6-p1+tuxcare of twig/twig. not_affected \u2014 CVE-2026-48808 does not affect Twig 2.15.6 because it specifically targets a vulnerability in sandboxing enabled through SourcePolicyInterface, which does not exist in this version. The target uses a fundamentally different architecture predating the SourcePolicyInterface feature.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-48808"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-48808 does not affect Twig 2.15.6 because it specifically targets a vulnerability in sandboxing enabled through SourcePolicyInterface, which does not exist in this version. The target uses a fundamentally different architecture predating the SourcePolicyInterface feature."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/twig/twig@v2.15.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-49981 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-49981"
      },
      "action_statement": "Vulnerability CVE-2026-49981 affects version v2.15.6-p1+tuxcare of twig/twig, and is fixed in v2.15.6-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 10.48.28-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 10.48.28-p1+tuxcare of laravel/framework, and is fixed in 10.48.28-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 10.48.28-p1+tuxcare of laravel/framework, and is fixed in 10.48.28-p2+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@10.48.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 10.48.28-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 10.48.28 does not contain the vulnerable code path. The vulnerability (GHSA-crmm-hgp2-wgrp) affects Laravel 11+'s LocalFilesystemAdapter class, which was introduced in Laravel 11 and does not exist in Laravel 10. Laravel 10 uses a delegating architecture where FilesystemAdapter throws RuntimeException for local filesystem temporary URLs rather than implementing them.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 10.48.28 does not contain the vulnerable code path. The vulnerability (GHSA-crmm-hgp2-wgrp) affects Laravel 11+'s LocalFilesystemAdapter class, which was introduced in Laravel 11 and does not exist in Laravel 10. Laravel 10 uses a delegating architecture where FilesystemAdapter throws RuntimeException for local filesystem temporary URLs rather than implementing them."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/polyfill-intl-idn@v1.30.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/polyfill-intl-idn@v1.30.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-46644 is fixed in version v1.30.0-p1+tuxcare of symfony/polyfill-intl-idn.",
      "vulnerability": {
        "name": "CVE-2026-46644"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpunit/phpunit@8.4.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpunit/phpunit@8.4.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 is fixed in version 8.4.3-p1+tuxcare of phpunit/phpunit.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 11.44.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 does not affect version 11.44.0-p2+tuxcare of laravel/framework. CVE-2026-24765 pertains to phpunit, not laravel/framework. Tracked on the phpunit VPV.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      },
      "impact_statement": "CVE-2026-24765 pertains to phpunit, not laravel/framework. Tracked on the phpunit VPV."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 11.44.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp is fixed in version 11.44.0-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.0-p5+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.0-p5+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.0-p5+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.0-p3+tuxcare does not have the vulnerable LocalFilesystemAdapter class or local filesystem temporary URL generation feature. The vulnerability exists in Laravel 11+ where LocalFilesystemAdapter was introduced. The target version uses FilesystemAdapter which explicitly rejects temporary URL generation for local filesystem adapters with a RuntimeException."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.0-p5+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.0-p5+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 9.52.21-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 9.52.21-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 9.52.21-p2+tuxcare of laravel/framework, and is fixed in 9.52.21-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 9.52.21-p2+tuxcare of laravel/framework, and is fixed in 9.52.21-p3+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@9.52.21-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 9.52.21-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 9.52.21 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability affects Laravel's LocalFilesystemAdapter class and its built-in local filesystem temporary URL generation feature, which was introduced in Laravel 11.x and does not exist in Laravel 9.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@6.4.13-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@6.4.13-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51736 is fixed in version 6.4.13-p2+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2024-51736"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@6.4.13-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@6.4.13-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24739 is fixed in version 6.4.13-p2+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2026-24739"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/bootstrap_site_alert@7.1.6-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/bootstrap_site_alert@7.1.6-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3901 is fixed in version 7.1.6-p1+tuxcare of drupal/bootstrap_site_alert.",
      "vulnerability": {
        "name": "CVE-2025-3901"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p4+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p4+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p4+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p4+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p7+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p7+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p7+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p7+tuxcare of craftcms/cms."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg is fixed in version 3.9.15-p7+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10090"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "AIKIDO-2025-10859"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-37251"
      },
      "impact_statement": "already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-31144"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33195"
      },
      "impact_statement": "already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33196"
      },
      "impact_statement": "not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-33197"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2023-33495"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36260"
      },
      "impact_statement": "not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-40035"
      },
      "impact_statement": "already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-41892"
      },
      "impact_statement": "already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification).",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-21622"
      },
      "impact_statement": "already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41800"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2024-52291"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52292 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-52292"
      },
      "action_statement": "Vulnerability CVE-2024-52292 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p8+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-52293"
      },
      "impact_statement": "already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-23209"
      },
      "impact_statement": "Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-32432 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. per review of Brhane",
      "vulnerability": {
        "name": "CVE-2025-32432"
      },
      "impact_statement": "per review of Brhane"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-35939"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46731 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "CVE-2025-46731"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-54417"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-57811 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-57811"
      },
      "action_statement": "Vulnerability CVE-2025-57811 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ...",
      "vulnerability": {
        "name": "CVE-2025-68436"
      },
      "impact_statement": "not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68437"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68454 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-68454"
      },
      "action_statement": "Vulnerability CVE-2025-68454 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-68455"
      },
      "impact_statement": "Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2025-68456"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-25491"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25493"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25494 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25494"
      },
      "action_statement": "Vulnerability CVE-2026-25494 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-25495"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25496 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25496"
      },
      "action_statement": "Vulnerability CVE-2026-25496 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25498 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-25498"
      },
      "action_statement": "Vulnerability CVE-2026-25498 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-27126"
      },
      "impact_statement": "Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27127"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-27128"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-27129 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-27129"
      },
      "action_statement": "Vulnerability CVE-2026-27129 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-28783"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-29069"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29113 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-29113"
      },
      "action_statement": "Vulnerability CVE-2026-29113 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-31857"
      },
      "impact_statement": "not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-31858"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-31859 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-31859"
      },
      "action_statement": "Vulnerability CVE-2026-31859 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32262 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32262"
      },
      "action_statement": "Vulnerability CVE-2026-32262 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-32263"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32264 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-32264"
      },
      "action_statement": "Vulnerability CVE-2026-32264 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "CVE-2026-32267"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33051"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33157 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33157"
      },
      "action_statement": "Vulnerability CVE-2026-33157 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33158 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33158"
      },
      "action_statement": "Vulnerability CVE-2026-33158 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33159 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33159"
      },
      "action_statement": "Vulnerability CVE-2026-33159 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33160 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33160"
      },
      "action_statement": "Vulnerability CVE-2026-33160 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33161 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-33161"
      },
      "action_statement": "Vulnerability CVE-2026-33161 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33162"
      },
      "impact_statement": "Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41129"
      },
      "impact_statement": "CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-41130"
      },
      "impact_statement": "not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55790 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55790"
      },
      "action_statement": "Vulnerability CVE-2026-55790 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-55793"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56381 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/...",
      "vulnerability": {
        "name": "CVE-2026-56381"
      },
      "impact_statement": "not_affected \u2014 Craft CMS 3.9.15 is NOT affected by CVE-2026-56381. The CVE explicitly states the vulnerability exists \"from version 5.0.0-RC1\", excluding version 3.9.15. Analysis confirms that both Twig (default autoescape='html' in Twig 2.x) and Vue 2 ({{ }} interpolation auto-escaping) provide runtime HTML escaping protection. User group names are rendered in templates/_includes/permissions.html, templates/..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56382 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56382"
      },
      "action_statement": "Vulnerability CVE-2026-56382 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56383 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56383"
      },
      "action_statement": "Vulnerability CVE-2026-56383 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56384 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56384"
      },
      "action_statement": "Vulnerability CVE-2026-56384 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56385 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56385"
      },
      "action_statement": "Vulnerability CVE-2026-56385 affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56394 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-56394"
      },
      "impact_statement": "The vulnerable assets/icon endpoint with the extension parameter does not exist in Craft CMS 3.9.15. This endpoint was introduced in version 4.0.0-RC1, which is later than the target version. Exhaustive searches found no controller action, route definition, or code accepting an extension parameter for icon operations. The only icon-related code (getIconPath in Assets service) is internal and not exposed via HTTP endpoints."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-3m9m-24vh-39wx"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-44px-qjjc-xrhq"
      },
      "action_statement": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare.",
      "vulnerability": {
        "name": "GHSA-6j87-m5qx-9fqp"
      },
      "action_statement": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p7+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-86vw-x4ww-x467"
      },
      "impact_statement": "not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-95wr-3f2v-v2wh does not affect version 3.9.15-p4+tuxcare of craftcms/cms. already_fixed \u2014 target already contains the fix / no backport applicable",
      "vulnerability": {
        "name": "GHSA-95wr-3f2v-v2wh"
      },
      "impact_statement": "already_fixed \u2014 target already contains the fix / no backport applicable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p4+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-c43v-4cr8-6mvp"
      },
      "impact_statement": "not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p4+tuxcare of craftcms/cms.",
      "vulnerability": {
        "name": "GHSA-g3hp-vvqf-8vw6"
      },
      "action_statement": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p4+tuxcare of craftcms/cms."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/craftcms/cms@3.9.15-p4+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare.",
      "vulnerability": {
        "name": "GHSA-x76w-8c62-48mg"
      },
      "action_statement": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p4+tuxcare of craftcms/cms, and is fixed in 3.9.15-p6+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/openid_connect@7.1.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/openid_connect@7.1.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3530 is fixed in version 7.1.3-p1+tuxcare of drupal/openid_connect.",
      "vulnerability": {
        "name": "CVE-2026-3530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/openid_connect@7.1.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/openid_connect@7.1.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3531 is fixed in version 7.1.3-p1+tuxcare of drupal/openid_connect.",
      "vulnerability": {
        "name": "CVE-2026-3531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/openid_connect@7.1.3-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/openid_connect@7.1.3-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3532 is fixed in version 7.1.3-p1+tuxcare of drupal/openid_connect.",
      "vulnerability": {
        "name": "CVE-2026-3532"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55568 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55568"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55767 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-55767"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59883 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-59883"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67339 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67339"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67353 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67353"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67354 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67354"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-67355 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-67355"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69245 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69245"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69246 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "CVE-2026-69246"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-94pj-82f3-465w is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-94pj-82f3-465w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-f283-ghqc-fg79 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-f283-ghqc-fg79"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-h95v-h523-3mw8 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-h95v-h523-3mw8"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/guzzlehttp/guzzle@7.10.0-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wm3w-8rrp-j577 is fixed in version 7.10.0-p3+tuxcare of guzzlehttp/guzzle.",
      "vulnerability": {
        "name": "GHSA-wm3w-8rrp-j577"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 11.44.0-p1+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24765 does not affect version 11.44.0-p1+tuxcare of laravel/framework. CVE-2026-24765 pertains to phpunit, not laravel/framework. Tracked on the phpunit VPV.",
      "vulnerability": {
        "name": "CVE-2026-24765"
      },
      "impact_statement": "CVE-2026-24765 pertains to phpunit, not laravel/framework. Tracked on the phpunit VPV."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq affects version 11.44.0-p1+tuxcare of laravel/framework, and is fixed in 11.44.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      },
      "action_statement": "Vulnerability GHSA-5vg9-5847-vvmq affects version 11.44.0-p1+tuxcare of laravel/framework, and is fixed in 11.44.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@11.44.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 11.44.0-p1+tuxcare of laravel/framework, and is fixed in 11.44.0-p2+tuxcare.",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "action_statement": "Vulnerability GHSA-crmm-hgp2-wgrp affects version 11.44.0-p1+tuxcare of laravel/framework, and is fixed in 11.44.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-21263 is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-21263"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 8.12.1-p2+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq",
      "vulnerability": {
        "name": "CVE-2021-43617"
      },
      "impact_statement": "GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43808 is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2021-43808"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52301 is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2024-52301"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "CVE-2025-27515"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 8.12.1-p2+tuxcare of laravel/framework. CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details.",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "CVE-2026-33347 in league/commonmark 1.6.7 is not affected. Refer to league/commonmark 1.6.7 for details."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-4mg9-vhxq-vm7j"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 8.12.1-p2+tuxcare of laravel/framework. not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 8.12.1 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns ambiguous URL parsing in local filesystem temporary signed URLs, but Laravel 8.x does not have the local filesystem signed URL feature. The temporaryUrl() method throws RuntimeException for local storage adapters. This feature was introduced in Laravel 11+/12.x."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jwvj-pwww-3mj5 is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-jwvj-pwww-3mj5"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-wq8p-mqvg-2p5h is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-wq8p-mqvg-2p5h"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@8.12.1-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 8.12.1-p2+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-x7p5-p2c9-phvg"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45067 is fixed in version v6.4.37-p2+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45067"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/mime@v6.4.37-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-45070 is fixed in version v6.4.37-p2+tuxcare of symfony/mime.",
      "vulnerability": {
        "name": "CVE-2026-45070"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2011-1939 affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2011-1939"
      },
      "action_statement": "Vulnerability CVE-2011-1939 affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-3363 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-3363"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-4451 affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2012-4451"
      },
      "action_statement": "Vulnerability CVE-2012-4451 affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-5657 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-5657"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6531 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6531"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2012-6532 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2012-6532"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2681 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2681"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2682 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2682"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2683 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2683"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2684 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2684"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-2685 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-2685"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8088 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8088"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2014-8089 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2014-8089"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-3154 affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "CVE-2015-3154"
      },
      "action_statement": "Vulnerability CVE-2015-3154 affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5161 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5161"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-5723 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-5723"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2015-7695 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2015-7695"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-4861 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-4861"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2016-6233 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "CVE-2016-6233"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-229x-22xc-2f2w is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-229x-22xc-2f2w"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-2x36-qhx3-7m5f is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-2x36-qhx3-7m5f"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-6fqw-j3vm-7f66 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-6fqw-j3vm-7f66"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-848f-mph5-9pm9 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-848f-mph5-9pm9"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8xhv-gqm4-3w99 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-8xhv-gqm4-3w99"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-9v78-h226-2rmq is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-9v78-h226-2rmq"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g52p-86j5-xr8q"
      },
      "action_statement": "Vulnerability GHSA-g52p-86j5-xr8q affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare.",
      "vulnerability": {
        "name": "GHSA-gff2-p6vm-3p8g"
      },
      "action_statement": "Vulnerability GHSA-gff2-p6vm-3p8g affects version 1.10.6-p2+tuxcare of zendframework/zendframework1, and is fixed in 1.10.6-p3+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-mhpx-3rv8-wrjm is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-mhpx-3rv8-wrjm"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/zendframework/zendframework1@1.10.6-p2+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-v42g-7q2x-cw32 is fixed in version 1.10.6-p2+tuxcare of zendframework/zendframework1.",
      "vulnerability": {
        "name": "GHSA-v42g-7q2x-cw32"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laminas/laminas-diactoros@1.8.7p2-1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laminas/laminas-diactoros@1.8.7p2-1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-31109 is fixed in version 1.8.7p2-1+tuxcare of laminas/laminas-diactoros.",
      "vulnerability": {
        "name": "CVE-2022-31109"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laminas/laminas-diactoros@1.8.7p2-1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laminas/laminas-diactoros@1.8.7p2-1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-29530 is fixed in version 1.8.7p2-1+tuxcare of laminas/laminas-diactoros.",
      "vulnerability": {
        "name": "CVE-2023-29530"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/flysystem@1.0.70-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/flysystem@1.0.70-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-32708 is fixed in version 1.0.70-p1+tuxcare of league/flysystem.",
      "vulnerability": {
        "name": "CVE-2021-32708"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/facebook_pixel@7.1.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/facebook_pixel@7.1.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-14557 is fixed in version 7.1.1-p1+tuxcare of drupal/facebook_pixel.",
      "vulnerability": {
        "name": "CVE-2025-14557"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2024-10189 is fixed in version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary.",
      "vulnerability": {
        "name": "AIKIDO-2024-10189"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48555 affects version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 10.15.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48555"
      },
      "action_statement": "Vulnerability CVE-2026-48555 affects version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 10.15.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/laravel-medialibrary@10.15.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-48557 affects version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 10.15.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-48557"
      },
      "action_statement": "Vulnerability CVE-2026-48557 affects version 10.15.0-p1+tuxcare of spatie/laravel-medialibrary, and is fixed in 10.15.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21544 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-21544"
      },
      "action_statement": "Vulnerability CVE-2024-21544 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21547 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-21547"
      },
      "action_statement": "Vulnerability CVE-2024-21547 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-21549 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2024-21549"
      },
      "action_statement": "Vulnerability CVE-2024-21549 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1022 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1022"
      },
      "action_statement": "Vulnerability CVE-2025-1022 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-1026 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-1026"
      },
      "action_statement": "Vulnerability CVE-2025-1026 affects version 4.4.0-p1+tuxcare of spatie/browsershot, and is fixed in 4.4.0-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/spatie/browsershot@4.4.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-3192 is fixed in version 4.4.0-p1+tuxcare of spatie/browsershot.",
      "vulnerability": {
        "name": "CVE-2025-3192"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability AIKIDO-2026-10659 is fixed in version 6.20.45-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "AIKIDO-2026-10659"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-27515 does not affect version 6.20.45-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-27515"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by CVE-2025-27515. The vulnerability requires the Rules\\File, Rules\\Password, and Rules\\Email custom validation rule classes introduced in Laravel 8+. Laravel 6 uses a fundamentally different validation architecture with built-in validators (validateFile, validateMimes, etc.) that do not exhibit the attribute name confusion flaw."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-5vg9-5847-vvmq is fixed in version 6.20.45-p3+tuxcare of laravel/framework.",
      "vulnerability": {
        "name": "GHSA-5vg9-5847-vvmq"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/laravel/framework@6.20.45-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 6.20.45-p3+tuxcare of laravel/framework. not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-crmm-hgp2-wgrp"
      },
      "impact_statement": "not_affected \u2014 Laravel 6.20.45 is not affected by GHSA-crmm-hgp2-wgrp. The vulnerability concerns LocalFilesystemAdapter's temporaryUrl() and temporaryUploadUrl() methods that create signed routes with inadequately encoded file paths. This class and feature do not exist in Laravel 6.x - they were introduced in Laravel 11.x. The target's FilesystemAdapter throws a RuntimeException when attempting to create tem..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/nesbot/carbon@1.39.1-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/nesbot/carbon@1.39.1-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-22145 is fixed in version 1.39.1-p1+tuxcare of nesbot/carbon.",
      "vulnerability": {
        "name": "CVE-2025-22145"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33182 is fixed in version 3.15.0-p1+tuxcare of saloonphp/saloon.",
      "vulnerability": {
        "name": "CVE-2026-33182"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33183 is fixed in version 3.15.0-p1+tuxcare of saloonphp/saloon.",
      "vulnerability": {
        "name": "CVE-2026-33183"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/saloonphp/saloon@3.15.0-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33942 is fixed in version 3.15.0-p1+tuxcare of saloonphp/saloon.",
      "vulnerability": {
        "name": "CVE-2026-33942"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46734 is fixed in version 1.6.7-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2025-46734"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-30838 is fixed in version 1.6.7-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "CVE-2026-30838"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-33347 does not affect version 1.6.7-p3+tuxcare of league/commonmark. The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-33347"
      },
      "impact_statement": "The affected files doesn't exist in the version 1.6.7 and also The GitHub Advisory (GHSA-hh8v-hgvp-g3f5) lists the vulnerable range as >= 2.3.0 <= 2.8.1"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71478 affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71478"
      },
      "action_statement": "Vulnerability CVE-2026-71478 affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-71488 affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-71488"
      },
      "action_statement": "Vulnerability CVE-2026-71488 affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-8rr7-cvq3-gmfh"
      },
      "action_statement": "Vulnerability GHSA-8rr7-cvq3-gmfh affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-c2pc-g5qf-rfrf is fixed in version 1.6.7-p3+tuxcare of league/commonmark.",
      "vulnerability": {
        "name": "GHSA-c2pc-g5qf-rfrf"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-g2gp-3wwq-f4ph"
      },
      "action_statement": "Vulnerability GHSA-g2gp-3wwq-f4ph affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-j8pm-gj4c-rq4x"
      },
      "action_statement": "Vulnerability GHSA-j8pm-gj4c-rq4x affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jfm3-95jq-q3rf"
      },
      "action_statement": "Vulnerability GHSA-jfm3-95jq-q3rf affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p4+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/league/commonmark@1.6.7-p3+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare.",
      "vulnerability": {
        "name": "GHSA-jjv6-8j6v-6j52"
      },
      "action_statement": "Vulnerability GHSA-jjv6-8j6v-6j52 affects version 1.6.7-p3+tuxcare of league/commonmark, and is fixed in 1.6.7-p5+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@6.4.13-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@6.4.13-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-51736 is fixed in version 6.4.13-p1+tuxcare of symfony/process.",
      "vulnerability": {
        "name": "CVE-2024-51736"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/symfony/process@6.4.13-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/symfony/process@6.4.13-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24739 affects version 6.4.13-p1+tuxcare of symfony/process, and is fixed in 6.4.13-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-24739"
      },
      "action_statement": "Vulnerability CVE-2026-24739 affects version 6.4.13-p1+tuxcare of symfony/process, and is fixed in 6.4.13-p2+tuxcare."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/term_reference_tree@7.1.11-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/term_reference_tree@7.1.11-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-4093 is fixed in version 7.1.11-p1+tuxcare of drupal/term_reference_tree.",
      "vulnerability": {
        "name": "CVE-2026-4093"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-13625 is fixed in version 5.2.28-p1+tuxcare of phpmailer/phpmailer.",
      "vulnerability": {
        "name": "CVE-2020-13625"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34551 is fixed in version 5.2.28-p1+tuxcare of phpmailer/phpmailer.",
      "vulnerability": {
        "name": "CVE-2021-34551"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/phpmailer/phpmailer@5.2.28-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3603 is fixed in version 5.2.28-p1+tuxcare of phpmailer/phpmailer.",
      "vulnerability": {
        "name": "CVE-2021-3603"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/drupal/commerce_paybox@7.1.5-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/drupal/commerce_paybox@7.1.5-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-0750 is fixed in version 7.1.5-p1+tuxcare of drupal/commerce_paybox.",
      "vulnerability": {
        "name": "CVE-2026-0750"
      }
    }
  ],
  "@id": "urn:sha256:adf034a0059b0a4d2e98d944ce40d722f1c832982005084c44639ec987ad7f90"
}
