{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1034937b-4233-56a6-9a66-567d16fbc417",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare",
      "type": "library",
      "group": "phpoffice",
      "name": "phpspreadsheet",
      "version": "4.5.0-p1+tuxcare",
      "purl": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3707cb40-8020-548e-8614-e0ac64d435d9",
      "id": "CVE-2025-54370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54370 is fixed in version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb12f11-937b-5ec9-b1bf-7c8d8fc06441",
      "id": "CVE-2026-34084",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34084 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8737d12e-76d5-59c5-b88e-7af694dd5bfa",
      "id": "CVE-2026-35453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-35453 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8f3c74a-a7c4-5369-918b-bc64153946ef",
      "id": "CVE-2026-40296",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40296 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c68c48b-da60-5249-8c25-c7297d466d68",
      "id": "CVE-2026-40863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40863 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd935ff1-4e57-5fc7-ae2c-019f1f8ca43f",
      "id": "CVE-2026-40902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40902 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01711593-7c14-5421-ab7b-9415ccee65a8",
      "id": "CVE-2026-59931",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-59931 does not affect version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet. not_affected \u2014 PhpSpreadsheet 4.5.0 is not affected by CVE-2026-59931. This CVE specifically describes a bypass of the domain whitelist feature via HTTP redirects. The domain whitelist was introduced in PhpSpreadsheet version 5.4.0, and the target version 4.5.0 predates this feature entirely. Since there is no domain whitelist in version 4.5.0, the whitelist bypass vulnerability described in CVE-2026-59931 do..."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03c3d6a-0379-501c-843f-368426dad4fa",
      "id": "CVE-2026-59932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59932 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9034b24-4462-5bbf-ac78-00aea19d3739",
      "id": "CVE-2026-59933",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59933 affects version 4.5.0-p1+tuxcare of phpoffice/phpspreadsheet."
      },
      "affects": [
        {
          "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/phpoffice/phpspreadsheet@4.5.0-p1+tuxcare"
    }
  ]
}