{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af52c21d-034a-5948-a83f-33ddbd1cdb39",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@5.0.2.post5+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.2.post5+tuxcare",
      "purl": "pkg:pypi/django@5.0.2.post5+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:942510e6-43e0-50ad-9297-8e6a1d764dd1",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128ecb2e-371b-58d4-a7c6-4a61de8f74bc",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b1771d-b49e-5898-a69a-a1da5463d3fc",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99265580-58c4-5b28-9362-a5ed168cda34",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b552b3b-be05-5758-ac7d-c068765be5a1",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6523e31-28a5-56d7-8a5a-39ed1a36f851",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d69ca630-ab76-5168-90bf-154937636900",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post5+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cbd80b6-180a-5c86-8b81-e094a185b99b",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e68283c2-21a7-5eac-aa6d-a10fe097141e",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63de528a-0711-5335-88bb-57276c957aa8",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9dbe487-8a4b-5a9f-85ae-694ada2cf901",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ba90cb-b38c-5e86-b12a-0f263b725e80",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d79c0a7-c1f7-5daf-a4ad-e413d2d58c67",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1198dd7-d5a7-5be5-9cdb-e1a4b1243277",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05811a41-c5c2-5c83-b9e8-5b8ae4f401c1",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90cfe671-ab2f-5eb7-926b-e0affab38d17",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd4d617-177b-55a4-b2e5-c4209afa4803",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e42a5e-ba60-533d-b692-ad27402226b4",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eac93ff-94f8-5873-9b08-a9711a9310aa",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6478406-5c05-5345-853a-1c35eec86c55",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2047131e-f1fd-5009-a534-c1c49c89a7c3",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea546b35-ea50-593a-b793-a0826dcebe32",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea36acf-cd86-582f-b244-057a732b3ccf",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba05c97c-f54c-5c44-9a16-cebe1fbeb675",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b5c4d8b-a935-54f5-a45c-600a7e6bc710",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc67519e-cf8e-554e-851e-c64d327bd1c6",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c3fd469-03dd-5de8-9564-c8a69d1c4b4d",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d29ed27-a44b-539f-9b4d-391cad56b7e3",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b7206cf-7950-550a-9211-bd5f9ed4f73b",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f3f4621-56fd-5956-b7ec-532a0f472c9b",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b813f9a-6456-540b-9dd1-c25815c58993",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03387057-c65b-5c7d-9524-37747c7c1c87",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post5+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b62bcd7-55fb-5f72-b6de-f97565e1df0c",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0014c8ff-daa9-5d2f-ba6d-bcd75ba5ad1d",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 5.0.2.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.0.2.post5+tuxcare"
    }
  ]
}