{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:032bcb80-8466-54be-9f9a-b97bf3264795",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p4+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e724f608-acb3-52d2-8d03-d7f2cf6425bd",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09a1b8d2-c279-55f4-a160-34e6f7f711b5",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29cf3ad6-fbbe-5c10-9ccb-9440d89de937",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7599a271-e8a0-5001-9256-d9c0065b3aa2",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bc3fb42-ed48-5e89-b413-7bb24bb3982f",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f818aa-6854-5a83-83d3-283eb7fd116e",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3303543a-c6fa-5a31-803b-ad0f9763d7d3",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4856bd7e-28d2-5fc7-8d66-10900a7f73b4",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d04fb2d-d3b2-5ce3-8c87-402def57fcbb",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b841a71-0cdf-5eef-a517-0866268d83ec",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c0536cc-210e-5c9b-94e7-220fc9a985dc",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b638c3ae-5000-5636-beea-ed8650344aea",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c75e6d6-d0a6-5a84-b5a3-9c0b1c53a51c",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e51c4f-dbff-54e5-b0c7-61f5b83c4d20",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39a43c3-68bd-591e-aaa5-7216179fd7e3",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af7ac30-aa0a-50d2-a92f-6acd4b7d9d92",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab853414-47ab-5a6d-9fe5-4039028d1f45",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8436284-905f-5ed4-b230-7cd38a06f65b",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p4+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13825afa-e951-58af-9715-75314b6bd69a",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p4+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p4+tuxcare"
    }
  ]
}