{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:585eaed3-f769-5e17-a5f6-4e5264d1ac4f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare",
      "type": "library",
      "group": "drupal",
      "name": "core",
      "version": "9.5.11-p5+tuxcare",
      "purl": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f0ff61e6-78ce-5363-baae-b31df6c9e0ca",
      "id": "CVE-2024-12393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12393 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de46e40e-db7a-5317-aff7-e33d11a61ae5",
      "id": "CVE-2024-45440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45440 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c280efd9-e83a-581f-a716-4b0f65d994e3",
      "id": "CVE-2024-55634",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55634 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c2d8dc-2126-5752-93d5-32a8a6aa0796",
      "id": "CVE-2024-55636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55636 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77590b62-a678-5889-8260-883bf0c50264",
      "id": "CVE-2024-55637",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55637 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:140b1551-149c-5f8c-8a93-42fb31e02257",
      "id": "CVE-2024-55638",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-55638 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba6fda5-d71c-5fe3-89a7-2a6898949084",
      "id": "CVE-2025-13080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13080 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c142184-6d5f-59f4-924b-551e8adc698e",
      "id": "CVE-2025-13081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13081 affects version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab079977-80ef-5f9e-b514-ac4a7e968678",
      "id": "CVE-2025-13082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13082 affects version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76ea08ef-a676-5ef9-9f4f-aa90d989a80a",
      "id": "CVE-2025-13083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13083 affects version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18103496-3f9d-574d-bbf0-a41fa1357f9a",
      "id": "CVE-2025-3057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-3057 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:043384c1-c945-57a1-9714-51f9174b2cf3",
      "id": "CVE-2025-31673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31673 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90eb8111-94bf-5f65-bcf8-3490f2675724",
      "id": "CVE-2025-31674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31674 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae2020c-9b1b-597d-95b7-ee5ea8ffd5a6",
      "id": "CVE-2025-31675",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31675 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b65549-2811-50c6-b043-244e6664f1af",
      "id": "CVE-2026-6365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6365 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf332cf-9692-5baa-9527-7481ed30bdc9",
      "id": "CVE-2026-6366",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6366 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ce267f-ff17-57ea-a967-dfb390348f57",
      "id": "CVE-2026-9082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-9082 is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2043292-bb00-56cd-9199-c01f396185c2",
      "id": "GHSA-6CCV-8FGF-CJPW",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-6CCV-8FGF-CJPW is fixed in version 9.5.11-p5+tuxcare of drupal/core."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39ba151a-51a8-5eb5-938a-e39ed886a6e3",
      "id": "GHSA-6ccv-8fgf-cjpw",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-6ccv-8fgf-cjpw does not affect version 9.5.11-p5+tuxcare of drupal/core. already_fixed \u2014 Target repository already contains the security fix for GHSA-6ccv-8fgf-cjpw. TuxCare backported the upstream patch in commit 2de76611 (PHPELSCVE-331), adding the missing NotFoundHttpException catch block to PathBasedBreadcrumbBuilder::getRequestForPath() that prevents denial-of-service attacks via crafted comment reply URLs."
      },
      "affects": [
        {
          "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/drupal/core@9.5.11-p5+tuxcare"
    }
  ]
}