{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0c7bb3a9-bcab-5099-9743-d16142e2d894",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "8.4.0.post4+tuxcare",
      "purl": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:34c9d1a7-3eb7-5e51-aa82-8e3666d61b94",
      "id": "CVE-2022-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22815 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fd30457-0188-5106-a842-c55a2fdf511d",
      "id": "CVE-2022-22816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22816 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cf21aee-ee0e-5379-b6de-50af6fd3e721",
      "id": "CVE-2022-22817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:922e4f93-5dd7-5878-bbbc-1edb779531b9",
      "id": "CVE-2022-24303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24303 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11673990-1e54-5263-b0fb-1de177044792",
      "id": "CVE-2022-45198",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:044065e2-6d42-577b-8b84-85033667b113",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c312fe42-8d5e-5c8f-8178-9b757311300c",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post4+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c0012e6-e993-53ca-a38b-811a32951930",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:972c7d84-2ca0-52d3-95df-043d660d4fd3",
      "id": "CVE-2024-21272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21272 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23409a8c-89fc-5d0c-a9a1-827359ca6202",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a635b2c3-1f95-5602-9045-99e39bfaeabd",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5988c50e-1741-582e-a185-aea9d6c5904a",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85c25432-e2ae-508a-8614-b62d6b46cc71",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c46cf1-18ab-51b9-a8a7-cb30d66cf5a6",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4298a00-759e-542a-beea-cb68fc6a9533",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:209ffcda-c3c4-56e1-83b0-dc853333c759",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:803f17dd-a708-54e7-95c5-1f1ac2a9385f",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96e9f5b4-7ba0-5603-89c7-ae870efcc2b4",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a4e8f00-fd9b-56e7-af39-80ac9940da12",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2068ab3-0864-5be1-bab9-3b22de84d215",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b7a952-c28e-574b-b06a-b7ec24e32cea",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4ce6752-130a-5d5d-bf60-23ae4317a705",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64febc1c-8c2d-5f30-8ab4-73776ba0bcef",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b577a775-4e4d-5ed0-9b5f-78708b2a0d11",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e02efcb-eea8-5f4e-9df7-dcca93ae14f2",
      "id": "GHSA-4fx9-vc88-q2xc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3a8ad2d-d182-5600-b28e-e75efc7c264d",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post4+tuxcare"
    }
  ]
}