{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:91215897-a378-5d1a-8af1-5d2bd9d799e9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "8.4.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b8ca8410-127d-5351-b547-40d44f1a8e9d",
      "id": "CVE-2022-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22815 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d6e385d-eb77-5140-a963-f24b847ce66b",
      "id": "CVE-2022-22816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22816 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4338ae3d-37d0-5c97-97bf-4ee1789f061a",
      "id": "CVE-2022-22817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bd6fc1c-5928-50cf-bab5-d96002d53ffc",
      "id": "CVE-2022-24303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24303 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42a96c5-3920-527b-911c-eeaab5bf3585",
      "id": "CVE-2022-45198",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71896fdd-bc0f-5c99-a893-a40248af7d25",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c13da22-9c10-5888-9e96-b0d58bfaf5c4",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post2+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af4c54c9-6077-510b-8fa9-2727435c73c8",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f866c3-4767-5b8b-b28e-622a0eddef39",
      "id": "CVE-2024-21272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21272 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f191696b-53a4-5f37-aee9-0bb6d32af5e4",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b74610c9-24b4-5540-b86c-67c6195fbee5",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:431d098a-7b09-51ad-ae92-f7b7de2fdcce",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fedfef2d-9601-5ac0-9ee2-eaa7643c7644",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aae0a5ea-6ee1-5ba1-99c9-3cee75599b8e",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6000c96-27de-546b-bd40-72abac57c209",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06c7941-8fe9-5a5a-9bde-06eb15f30378",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a18bab-8208-5f07-ae04-c88b500ef8a2",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c04c18c3-367d-5abd-b948-104fa094e263",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8ca872d-79b5-5ddc-91d5-de64faad78fa",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32faf680-d5ec-5dac-b1fe-ec063d80ef1a",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c25d7678-56e9-5a4c-a224-d4f4ba10e3d1",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77ef0f93-fb7d-5cc7-b5c9-c181810aebdb",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3734bbc5-0288-5865-9bce-bf926f2ffb7e",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e98eba-1e3c-5901-a1b4-d8a6a8cea38d",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d937e34c-899c-5839-abd5-cc541f4aa8c0",
      "id": "GHSA-4fx9-vc88-q2xc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb2219f8-ecce-5c3a-afe1-8d46d05794bf",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post2+tuxcare"
    }
  ]
}