{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:780075b9-2b52-5382-bad1-f9cc27c95dcb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.2.post12+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.2.post12+tuxcare",
      "purl": "pkg:pypi/django@4.2.post12+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6ce4e53d-d6fc-5514-9bf3-df8069808abd",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648d5521-1ba4-5190-bbd4-d20cef18389b",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8d00692-c190-5a50-93fd-87e2d990330a",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3356c288-82ee-5fe7-995e-c8f78c462c91",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:758a54c6-629e-5550-a5c5-2bda99a1d302",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c0ce024-9c43-5fd5-833b-9714ac5a4636",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78867335-5df2-5be3-bc85-4bd522c3aed4",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6680d845-913a-51e9-8bcf-90dc6d19deb6",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1925ebff-3351-5739-ab0d-a90d0430fe63",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:149e1306-a374-5bf9-a5af-8d734e93b982",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26716e47-3388-5658-8089-4dcacf5c232d",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb85f8fc-d7e2-5eb4-8fec-9555459a0ff3",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51805d7b-1fdd-5e5d-af50-8594c7c4fdf0",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06bcd46d-b482-55e2-8921-052b005f37dc",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04909f89-65d6-5311-90d0-d1aabeae6c42",
      "id": "CVE-2026-25673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1184354-5db1-5228-8279-86aaf3a9c859",
      "id": "CVE-2026-25674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70e7b845-7406-5ca9-a779-17af15e51c8a",
      "id": "CVE-2026-33033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dbb8275-25a1-5d32-aaec-e45dbae251cf",
      "id": "CVE-2026-33034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7aa72f1-007c-5c4b-8c52-0783dd2a534b",
      "id": "CVE-2026-3902",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5e44705-06a0-5c69-8fef-e453efe82396",
      "id": "CVE-2026-4277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d6af52-f9e3-540a-affd-068f9d04792f",
      "id": "CVE-2026-4292",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ac9649d-9e94-51f9-9249-694005bbaf7d",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48587 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec6c3e46-f512-5956-8276-2640afe3e458",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eea3a7d-2899-509b-8ef1-73bc78433e47",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ca9822b-b3e5-5ae7-9525-b11108dffa69",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.2.post12+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46367860-9e49-506e-b0cb-3a3ba3680345",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bb659b7-a53a-56fe-a24d-a78b4d26f81e",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 4.2.post12+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post12+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.2.post12+tuxcare"
    }
  ]
}