{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7f42776f-c9a7-568f-afcd-49cba6db2a87",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/keras@2.15.0.post2+tuxcare",
      "type": "library",
      "name": "keras",
      "version": "2.15.0.post2+tuxcare",
      "purl": "pkg:pypi/keras@2.15.0.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fe3d5c57-3085-55f8-be77-2c5d9dfe651f",
      "id": "CVE-2024-3660",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3660 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceff3aba-ac48-51c9-b815-be795d76a550",
      "id": "CVE-2024-55459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-55459 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5de362bc-6ea0-5ab1-8f60-9a706fafad2d",
      "id": "CVE-2025-12058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-12058 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3defe6ce-aec0-5b9c-b5a3-45c71a4d7a72",
      "id": "CVE-2025-12060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-12060 is fixed in version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa083a8c-dd94-5940-a8e6-ecabb355dcf4",
      "id": "CVE-2025-12638",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-12638 is a false positive for keras 2.15.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:310e9271-85c7-5bf7-a7cd-8354466ae578",
      "id": "CVE-2025-9906",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-9906 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db9d7c38-476f-5920-aa3b-596a5e5d98f7",
      "id": "CVE-2026-0897",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0897 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d830791a-2ca7-5532-90a3-b420b44f83d3",
      "id": "CVE-2026-11816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-11816 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff44b21-94b8-51f1-b5f2-2fb9b4c226ef",
      "id": "CVE-2026-12479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12479 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6a5eed-11aa-5abb-8588-867c89976db6",
      "id": "CVE-2026-12480",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12480 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c75b27c-76a7-58a9-b84e-291c05ac33b4",
      "id": "CVE-2026-12481",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12481 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:335fa319-a6b5-5e42-97b8-cd215f69614f",
      "id": "CVE-2026-12482",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12482 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1a844a5-86b4-5625-8dc3-b7d972d9ec43",
      "id": "CVE-2026-12484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12484 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e71f7e3-d097-5316-bc21-fdc742edc9b0",
      "id": "CVE-2026-1462",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post2+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462"
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ad3b4b-e27a-50a7-9d87-b1df3dbb3f89",
      "id": "CVE-2026-9335",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-9335 affects version 2.15.0.post2+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f37c19ee-9865-505e-9f39-226cdd4a99c3",
      "id": "GHSA-28jp-44vh-q42h",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-28jp-44vh-q42h is a false positive for keras 2.15.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c71050-45e0-509a-9ace-08524327e2c6",
      "id": "GHSA-5478-v2w6-c6q7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-5478-v2w6-c6q7 is a false positive for keras 2.15.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/keras@2.15.0.post2+tuxcare"
    }
  ]
}