{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b3e1b547-9753-5ae8-8275-b4a507251924",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.0.post17+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post17+tuxcare",
      "purl": "pkg:pypi/django@4.0.post17+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7ce26b13-c0af-53f2-9fb2-dfe84d012432",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e8e004e-7525-5f9a-9540-097a159cf91b",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b0dc918-6f70-5c27-86c1-720fb35a81b1",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366d7b29-518a-543b-8ee7-bcb0410d520e",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d356a4d7-f617-594e-a289-35bf5a6ecfa2",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27de794-503d-51e7-8b3d-fea04212307c",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c558b576-38f0-5e09-afae-0e315a254c24",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c120b43-68f8-57b8-a6cd-c0dc57e28117",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc36ea14-9f65-59ee-b9bf-8e91bd299c7f",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34b70011-284d-59cd-a552-c2bdd79b0364",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16bcc311-f0a5-535c-9f1b-46443b6db787",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a2934c1-621f-5368-a242-19676747062a",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e245c409-4448-5256-827b-46df6cb82ce9",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b56f3b1-ae92-5106-afd5-c35509f7656d",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99004854-cae2-5cc4-be65-43dc16d7d5bf",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39797436-d2c2-5458-bbb1-e382dbe492be",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cf0af7c-0ac0-5567-b052-bd469dd84858",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d3cb26a-359c-5a60-aed9-14ae365580a0",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86cb5978-de0d-521f-828f-7e0e463b8714",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90362a94-f4f5-5b6d-a1b3-0bdcfe790400",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e5044dd-9cb0-59e6-af9d-efe7cf75bd36",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c8bbff-4ad0-5184-8b7a-bb1315a34f3d",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ee5104-d4e9-53b5-8f7e-be30e9cd04dc",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5534929f-db1e-5e8f-80a6-c0dc1b2cc644",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59813386-c06f-5f58-befb-bfe97127c1e9",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ed3599-837a-50d6-8ad1-6e91d103ed92",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bad37a-c220-5cd3-ba7e-b9ec5a301930",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18dc5130-1493-5aad-a529-43b0af08acdc",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07aec35-70d1-54f6-a662-d8633eafe56a",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dcd678e-f206-58bc-a552-4f639d7321ee",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b24eee60-742a-550d-9a4a-77adda86667b",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4019d13-7a2d-529d-813f-4ecd1b669c62",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a5bbe1-8f24-523b-a70b-2ac8265c7c4d",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.0.post17+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f65b650b-433e-5ac8-9c3a-d5592000b102",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7de499ab-34d7-5ad1-a9f4-d4a619fed012",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 4.0.post17+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post17+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.0.post17+tuxcare"
    }
  ]
}