{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6a966726-4caf-5629-95a2-1ee42e24cca8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare",
      "type": "library",
      "group": "laravel",
      "name": "framework",
      "version": "5.6.40-p1+tuxcare",
      "purl": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:547962b6-6cea-5b7f-bb2b-0602a20dde2a",
      "id": "CVE-2020-19316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-19316 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae62f0e4-f63e-58ff-9f09-c18c803067d1",
      "id": "CVE-2020-24941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-24941 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a757e40-a69b-5479-97e4-6a21530486b8",
      "id": "CVE-2021-21263",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21263 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4549f816-4e7b-5041-93cf-cafe3af05ab6",
      "id": "CVE-2021-43503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43503 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f963e17c-9eab-5a14-9792-8c0370192ebe",
      "id": "CVE-2021-43617",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-43617 is a false positive for laravel/framework 5.6.40-p1+tuxcare. GitHub advisory GHSA-364w-9g92-3grq is withdrawn \u2014 https://github.com/advisories/GHSA-364w-9g92-3grq"
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d43004-a15f-564a-bb0a-d2f25ce04e6c",
      "id": "CVE-2021-43808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43808 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c383eb-1539-5b2e-b8df-9bea6f810406",
      "id": "CVE-2022-31279",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31279 is a false positive for laravel/framework 5.6.40-p1+tuxcare. CVE-2022-31279 was REJECTED/withdrawn by its CNA per NVD: \"DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.\""
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98f369c8-ebc8-55ba-86c9-7b54f3381d94",
      "id": "CVE-2024-52301",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52301 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1173bad-2073-5100-b767-0e95c8672ed0",
      "id": "CVE-2025-27515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27515 is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9682fe-1ccb-5fe3-9421-92a7c09a62f2",
      "id": "GHSA-4mg9-vhxq-vm7j",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4mg9-vhxq-vm7j is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27d51d52-6882-5439-b52e-f73307410faf",
      "id": "GHSA-5vg9-5847-vvmq",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-5vg9-5847-vvmq does not affect version 5.6.40-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40-p1+tuxcare uses SwiftMailer 6.3.0, not the Symfony Mailer targeted by GHSA-5vg9-5847-vvmq. SwiftMailer's Egulias EmailValidator provides CRLF validation that prevents the vulnerability pattern from manifesting."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1164379e-150f-5f92-b768-95459cb2b5f1",
      "id": "GHSA-crmm-hgp2-wgrp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-crmm-hgp2-wgrp does not affect version 5.6.40-p1+tuxcare of laravel/framework. not_affected \u2014 Laravel 5.6.40 does not have the vulnerable LocalFilesystemAdapter class or signed URL generation for local filesystem. The feature was introduced in Laravel 11+ (September 2024), years after this version. The FilesystemAdapter.temporaryUrl() method explicitly throws RuntimeException for local adapters - the feature is unsupported."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03873c12-7951-5f72-ade0-9e2426eb00c6",
      "id": "GHSA-qm5c-m76r-2hfr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qm5c-m76r-2hfr is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90b3508c-ca9b-5738-8c41-5d69d95d7684",
      "id": "GHSA-x7p5-p2c9-phvg",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-x7p5-p2c9-phvg is fixed in version 5.6.40-p1+tuxcare of laravel/framework."
      },
      "affects": [
        {
          "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/laravel/framework@5.6.40-p1+tuxcare"
    }
  ]
}