{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d0656f04-d1de-5827-a08c-c9a337f78c19",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.2.post11+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.2.post11+tuxcare",
      "purl": "pkg:pypi/django@4.2.post11+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1b0f18a3-7068-5bf7-a4a7-14bf6e73845b",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff945fa-fd36-5800-8a1b-4ea4edb5c771",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170a5be2-1fb9-563c-a056-e24dbc1e8bc5",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea417dde-0574-5381-9468-661cb9585e1a",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30f68d12-8421-5180-80ec-f4da537a0ff3",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5166c8dd-2641-5f40-ad83-c4856b7ee29a",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c82fc8f-3655-5429-84ce-136f58277889",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f54eb434-dd44-5e8d-b290-f74915458b68",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a88d983a-30a2-52c5-bd68-4a9aff4d95f4",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e966c11-ea1e-5755-87e8-3e70fffad7ee",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ace911a-0e2c-5b37-8fcf-a47d248a5215",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2dfdaf0-a11c-5827-b64e-f994b379c4a0",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2815cc80-9687-5cb5-9fe3-0ff4d8fae468",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a37f25a-7ef7-530c-bdb0-486a2f0d9ffb",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a8f6184-fbba-512b-9c89-090b1bd6558d",
      "id": "CVE-2026-25673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b065b78d-fe8f-5bd5-b641-c8aecd737e8c",
      "id": "CVE-2026-25674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c5b8013-58a4-5aa8-9f8c-6ad9a0a4db5f",
      "id": "CVE-2026-33033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44557000-8efd-54a8-97f9-d9f1e1f405ec",
      "id": "CVE-2026-33034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2e7a22f-c546-5b70-bb66-57255d3db2ad",
      "id": "CVE-2026-3902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5219572a-9bac-5cde-8fec-6689b599fc1e",
      "id": "CVE-2026-4277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a2bac2-c8d2-53ba-b79e-8c560c56f9b2",
      "id": "CVE-2026-4292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f524353-d789-5305-88a9-4a9cb91d74b2",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d86f5d8-b17e-52dd-a552-fb3ceb3e5d10",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7f66238-7fe8-5b7c-91bb-e07d96c8de9c",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de4a92c7-8711-528d-b6d0-da1e482e582e",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.2.post11+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb55436-70ac-5bdf-8adc-c76508977b36",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78f27625-2b44-530e-abc4-24626be3d7c1",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 4.2.post11+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post11+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.2.post11+tuxcare"
    }
  ]
}