{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5453a131-969a-5bc8-a156-9ee62453e86c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@5.0.2.post4+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.2.post4+tuxcare",
      "purl": "pkg:pypi/django@5.0.2.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:250f3ec5-128b-55da-8338-73ed58212960",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a085305-4bff-5989-8081-40845411a69c",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cedee7bb-f5ab-57fc-99d1-aa9cd1b51963",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cea53a5-8bea-520f-b559-f373f9c43865",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:839fe85e-ef5a-549a-a99f-b242b1921597",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79cab13-7188-5b53-9161-a42ff33405bc",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15595952-008f-597f-a2a3-aec743442865",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post4+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:804a9dd5-fbc4-51dc-8469-e5571179054a",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:751593c8-f4c8-54ea-b070-db814bf39d4d",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a2f334-d13e-5d42-9676-12575689eeed",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77d16f90-50ca-5f2d-bd1c-7b790dd6f78b",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f51572-b18f-5dd8-b5e7-35fcff7ac05d",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0dca67d-5175-5616-bd7c-a5de2b7f9e33",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ea7f6d7-2f08-5fdf-9f1b-5cc8ec6175c4",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a2637c-4e51-583a-9f4b-4bdf6b2a31fe",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8b0fae4-d57c-50b2-baf8-9efaed0ba405",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec46b8fc-37a0-5dd7-a3e8-65eefa5def4f",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6726301c-0bbf-5eef-836e-0b02e4fb764a",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:440716ca-5b39-55b2-bcc4-29ae56c3ff33",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ac8c364-f2ab-5309-a73d-64de1d6d95fc",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884b4e3d-2ab1-5fb1-ba63-e4f80eac598d",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d9f35cd-56cf-5445-a4bd-cd2ad5e2c4f5",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e92c28-35e8-56a8-8f0b-bfe2881aaae1",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:054fa267-ac1f-5130-819c-a3e48c99c775",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61e998e-b2c3-5e39-931e-8b7d14409724",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ea7a32b-ef91-519e-85ce-715bed645809",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e398795-8675-5b56-b754-d454b5bba56a",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a89f1b70-62c3-52a8-8d39-e3666e4aab79",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da2264fa-7119-55b2-b448-092095f8dc20",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bd34d6e-4fc9-54b1-8728-b4c5488a3364",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25922ddb-6096-5b90-83bc-5ad2fe274a56",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2de09b3e-79cf-5f8b-9f9d-70256c79686d",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post4+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcd81dd4-48bc-55e9-9d88-2462ba2cd120",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f7e765b-9712-5c50-86e2-d024c3be2093",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 5.0.2.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.0.2.post4+tuxcare"
    }
  ]
}