{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c9ab8539-8acb-5e1c-bf2c-3fd60cd24e4b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.2.post10+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.2.post10+tuxcare",
      "purl": "pkg:pypi/django@4.2.post10+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:16c44fc5-a4bc-58f1-a9b0-bb49039129cc",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0582321b-6eb7-509a-95b0-ef4234eec619",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae54569-407c-5ce8-876f-6f3d223da27d",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:646ee4f6-6b8f-59ca-a892-fda2dad5cf49",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05a6317f-a795-5b23-9f0f-e48dd33b71d1",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29cecf06-7697-50fb-81f3-46064546bf0f",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c1e54b1-3a4b-5b95-9c34-5068ed839fdd",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c88ecdb-d616-5a27-a0c5-2cf5e54b198f",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d847597d-4302-5366-8601-0caa35af0ada",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8533a21-93c6-5f20-983d-0bebbefa4fda",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e051f243-3da1-5f9a-abc6-c31e9c5ee25d",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49dd7b4d-1d17-5603-804e-3d6772f328e3",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4ecb286-2d72-543c-85c9-4164a0a136d1",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2408157b-2952-508a-b031-263742a33563",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230fe4df-ab26-52bf-9961-c3c22b2385e1",
      "id": "CVE-2026-25673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aacd4062-853d-5e2c-8f96-69a94b15b09a",
      "id": "CVE-2026-25674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14e9e495-101c-5989-bb87-a91d218b1959",
      "id": "CVE-2026-33033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:657817cb-7db9-571e-84d9-5552633559b1",
      "id": "CVE-2026-33034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b881156b-e3a3-59af-aa6b-f1f808ca1fd0",
      "id": "CVE-2026-3902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a64fc9c-49bc-5d55-8d7c-3f26adb9c740",
      "id": "CVE-2026-4277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b10a3c27-8e9c-5811-a3a3-fb71af083539",
      "id": "CVE-2026-4292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d5cfbf-de3d-5878-95cd-560eae67c636",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda9d88a-92c9-5703-9f14-47a8a456b25c",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3fc4d25-7a1c-5e5b-8225-889481f9217e",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ac32d3-74cc-53e3-ae78-ba65449f001f",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.2.post10+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0273bc1b-eb6d-5dff-8a42-128094d696a2",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fec6bcb-1c69-52de-a879-6c01b0ee29a6",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 4.2.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post10+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.2.post10+tuxcare"
    }
  ]
}