{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:359b1fcf-1429-5228-bd72-885b83f27820",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.5.0.post5+tuxcare",
      "purl": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ce1adc89-8ba4-59f2-a91d-3d5f09b046c9",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eb6b883-6f6d-5059-b1ef-9e9b7ae81a22",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f3d5ef-798a-5915-85c0-d31a462ff329",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b943eeb6-ccb9-5144-8e15-850fb04b199b",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad8e3304-4311-5191-9317-53b35c5d60ac",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2afb2227-eb68-5bf6-a3db-8ef15e2dc4ce",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca5daeb-ae81-501e-a331-035e6818fac1",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd7733d-9ccd-5434-b7e3-345727f7ce20",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945ab5ed-0a85-5e1d-a381-f03fb5b30598",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:817703db-5688-5273-bf4f-716e56b319fc",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20802772-ef73-5b4e-9be6-5d6a82292c2c",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1c560f6-34b3-5f38-b491-8fe954401446",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfea5027-345d-5f83-86e3-9c183f451020",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:131a9f01-474e-5891-896f-11e275432fa2",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2acd203b-28e5-5883-9c8d-320363e7c08b",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d678b6a3-21c0-5ac2-9da8-f07f00f51196",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ebdc59a-68c1-51b7-87d6-5b655825538e",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a9046f-f590-5e9f-88c5-09439680b046",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.5.0.post5+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da733b68-a292-58a7-8e68-d9031f002ee2",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post5+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.5.0.post5+tuxcare"
    }
  ]
}