{
    "@context": "https://openvex.dev/ns/v0.2.0",
    "@id": "https://php.net/sbom/windows/php/8.6.0beta2/vex/e0f19229-fa2f-44ae-8312-a42cf44d26c4",
    "author": "PHP Group",
    "timestamp": "2026-08-25T14:57:27Z",
    "version": 1,
    "statements": [
        {
            "vulnerability": {
                "name": "CVE-1999-0289"
            },
            "timestamp": "2026-07-18T08:35:15Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/apache@2.4.68",
                    "identifiers": {
                        "purl": "pkg:generic/apache-httpd@2.4.68"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "vulnerable_code_not_present",
            "impact_statement": "The affected legacy Win32 path handling is not present in Apache HTTP Server 2.4 builds."
        },
        {
            "vulnerability": {
                "name": "CVE-1999-0678"
            },
            "timestamp": "2026-07-18T08:35:15Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/apache@2.4.68",
                    "identifiers": {
                        "purl": "pkg:generic/apache-httpd@2.4.68"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "component_not_present",
            "impact_statement": "This CVE concerns a Debian default ServerRoot configuration; Debian packaging and configuration are not present in the Windows artifact."
        },
        {
            "vulnerability": {
                "name": "CVE-2025-3891"
            },
            "timestamp": "2026-07-18T08:35:15Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/apache@2.4.68",
                    "identifiers": {
                        "purl": "pkg:generic/apache-httpd@2.4.68"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "component_not_present",
            "impact_statement": "This CVE affects mod_auth_openidc, which is a separate module and is not included in the Apache dependency artifact."
        },
        {
            "vulnerability": {
                "name": "CVE-2017-8806"
            },
            "timestamp": "2026-08-15T04:25:25Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libpq@16.15",
                    "identifiers": {
                        "purl": "pkg:generic/postgresql@16.15"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "component_not_present",
            "impact_statement": "This CVE affects Debian and Ubuntu postgresql-common cluster scripts, which are not included in the Windows libpq artifact."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-7598"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting upstream username_len bounds checking in src/userauth.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2025-15661"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream bounds-checked parsing for malformed SFTP symlink responses in src/sftp.c and the follow-up SSH_FXP_STATUS response handling fix."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-55199"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream parse-failure handling for SSH_MSG_EXT_INFO extension name and value strings in src/packet.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-55200"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream packet length upper-bound validation in src/transport.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-58050"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream bounds checking for public-key attribute counts in src/publickey.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-58051"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream initialization of newly allocated public-key list entries in src/publickey.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-66032"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream nullification of freed SFTP response data in src/sftp.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-66033"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream runtime bounds checks for AES-GCM block processing in src/openssl.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-66034"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream bounds checking for public-key comment lengths in src/publickey.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-66035"
            },
            "timestamp": "2026-08-25T13:00:13Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libssh2@1.11.1-8",
                    "identifiers": {
                        "purl": "pkg:generic/libssh2@1.11.1"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream lower-bound validation for Encrypt-then-MAC packet decryption in src/transport.c."
        },
        {
            "vulnerability": {
                "name": "CVE-2023-52356"
            },
            "timestamp": "2026-08-04T04:11:38Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libtiff@4.7.2",
                    "identifiers": {
                        "purl": "pkg:generic/libtiff@4.7.2"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "vulnerable_code_not_present",
            "impact_statement": "The upstream TIFFReadRGBATileExt validation fix is included in libtiff 4.7.2; Grype matches this CVE without a version constraint."
        },
        {
            "vulnerability": {
                "name": "CVE-2023-6277"
            },
            "timestamp": "2026-08-04T04:11:38Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libtiff@4.7.2",
                    "identifiers": {
                        "purl": "pkg:generic/libtiff@4.7.2"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "vulnerable_code_not_present",
            "impact_statement": "The upstream memory-allocation validation fix is included in libtiff 4.7.2; Grype matches this CVE without a version constraint."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-4775"
            },
            "timestamp": "2026-08-04T04:11:38Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libtiff@4.7.2",
                    "identifiers": {
                        "purl": "pkg:generic/libtiff@4.7.2"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "vulnerable_code_not_present",
            "impact_statement": "The upstream integer-overflow fix is included in libtiff 4.7.2; Grype matches this CVE without a version constraint."
        },
        {
            "vulnerability": {
                "name": "CVE-2023-6228"
            },
            "timestamp": "2026-08-04T04:11:38Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libtiff@4.7.2",
                    "identifiers": {
                        "purl": "pkg:generic/libtiff@4.7.2"
                    }
                }
            ],
            "status": "not_affected",
            "justification": "component_not_present",
            "impact_statement": "This CVE affects the tiffcp command-line utility, which is not included in the Winlibs libtiff dependency artifact."
        },
        {
            "vulnerability": {
                "name": "CVE-2026-11979"
            },
            "timestamp": "2026-08-12T08:05:01Z",
            "products": [
                {
                    "@id": "pkg:php-windows-deps/libxml2@2.15.3-1",
                    "identifiers": {
                        "purl": "pkg:generic/libxml2@2.15.3"
                    }
                }
            ],
            "status": "fixed",
            "action_statement": "Fixed by backporting the upstream bounds checks for xmlcatalog --shell command and argument parsing in winlibs/libxml2 tag libxml2-2.15.3-1."
        }
    ]
}
