{
  "@id": "urn:uuid:2a9da613-aba7-45cd-b3a0-0b16ce323ab9",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3838 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3838"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3902 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2021-3902"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-0085 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-0085"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2400 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-2400"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-28368 does not affect version 1.2.2-p1+tuxcare of dompdf/dompdf. already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-28368"
      },
      "impact_statement": "already_fixed \u2014 The target repository already contains the exact fix for CVE-2022-28368. TuxCare applied this fix via commit 81f4dff (PHPELSCVE-193) on December 11, 2025, which implements the identical mitigation as the upstream vendor patch: determining the cached font file extension from the parsed font type rather than from the attacker-controlled URL."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-41343 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2022-41343"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-23924 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-23924"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-50262 is fixed in version 1.2.2-p1+tuxcare of dompdf/dompdf.",
      "vulnerability": {
        "name": "CVE-2023-50262"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55554 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55554"
      },
      "action_statement": "Vulnerability CVE-2026-55554 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-55555 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-55555"
      },
      "action_statement": "Vulnerability CVE-2026-55555 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-56722 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-56722"
      },
      "action_statement": "Vulnerability CVE-2026-56722 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59941 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59941"
      },
      "action_statement": "Vulnerability CVE-2026-59941 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59942 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59942"
      },
      "action_statement": "Vulnerability CVE-2026-59942 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare",
          "identifiers": {
            "purl": "pkg:composer/dompdf/dompdf@1.2.2-p1+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59943 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59943"
      },
      "action_statement": "Vulnerability CVE-2026-59943 affects version 1.2.2-p1+tuxcare of dompdf/dompdf, and is fixed in 1.2.2-p2+tuxcare."
    }
  ]
}
