{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ce47d8b6-3602-54a3-9140-fec72241dc3a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.0.post10+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post10+tuxcare",
      "purl": "pkg:pypi/django@4.0.post10+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:71a63f79-ca53-576f-92bf-319b2afb84db",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a1f769c-9000-5ada-b4f1-3ab222b95a8e",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94e13fa-1538-5ea3-ac46-fa31fe5b9614",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55578bd7-f157-5787-8669-c073899d548b",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b672ad-cbab-5def-b410-72463c1bfc9f",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e8d1959-596d-50e8-bd6b-5b68c177d4ce",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0411b74-4ec3-592b-8ee3-1c3ae2b5c336",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:139808e4-8187-5254-b838-b0fd93a3df6d",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4003afd7-63eb-5a3b-a402-06130ccbff02",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:603a6f94-10b3-5fdf-9e2a-f0b225c98f0f",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18290057-cf52-586b-99b0-77fe5149ac64",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a58e0bf-710a-5b40-a823-d3013691f59f",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:832280ff-5c64-573c-8a8d-fc6700cd2ec8",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad87191b-ffde-52ea-b2b0-50aa968860fe",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f6915c-aa88-5080-947c-2a8b80d87dcc",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38a50027-7a88-5958-9bce-3e957f47f017",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c84c90d-9d50-56d3-a223-2db592751be7",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bebc6b7-2441-5af3-afd9-b478dd34024b",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:776e617d-733f-512a-9102-427808caae3a",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4546af8a-943a-5544-8a2c-9cbde262bdf3",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12965ec9-5d10-5785-9f12-b933e71a699f",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:321b5fd2-e907-5940-8665-0ed2215cc914",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56471714-5562-5f5c-bb1a-9a2d3464663d",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:354eda10-7ba8-5cd5-be14-1e19b8e852dd",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:286f0ca2-86c0-5eff-8a51-6c9815b527be",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfce99e6-39b5-54aa-9447-a6527130202a",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c68ecdcf-0c97-5fd8-90e1-c5ec93bafdcb",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d70f93c-dedc-5c1a-aaca-0ef23a0c1aa8",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:939f175a-c68b-57ec-9008-3bbaae174c1a",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02d95116-2fda-5340-9fe8-7e0f9bfee244",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e9c4484-14c4-511b-b0cb-7741ce1fa197",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f37b27-dae4-5e1a-837e-70acdad10710",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33352af-a525-590c-8b2a-ddb9a1b78201",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.0.post10+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ac56036-7c45-54ac-982b-e464f074438c",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cf3d6a0-700e-516b-b172-3f6aa43aacda",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 4.0.post10+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post10+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.0.post10+tuxcare"
    }
  ]
}