{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6c0d0d48-2f60-5fd6-9986-5ee84ae164c7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.5.0.post3+tuxcare",
      "purl": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d65b4782-bae4-5679-8344-a60e0842d2d1",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d95d759c-2024-5426-97f1-4a31efd26fcc",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c5999fe-8a93-5a78-82d3-3dfaac3cb0d1",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac7ce90-26c3-563c-aa5b-88a423565b28",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:136f9acf-76b5-5695-8e31-0043d1f519ba",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d7187e-dfe1-5a5e-aa5f-2dbe030c4366",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b1640ea-565c-5c37-978c-4de912ea5bf2",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7032ac8e-fb4f-524c-a3bf-ed02bfeb27c7",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a14c84-c01b-5d07-b215-da0f4bd2a7da",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ee061c-c140-5d0d-b248-15978174ea3d",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175acd5d-f391-574c-b346-60e8ede990e6",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0224ad03-4690-54bf-80c6-81b279c9f63c",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a197b7c9-063c-51d5-8867-2ff7ac627106",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1074f8d-acba-542e-ac2c-262150b0fa72",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf1cb4e2-8902-5b0e-9bfb-d50bfac4bf49",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ea89398-c267-5adb-b4c6-4604f33c6b0e",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0504a247-eae0-5bf5-9ced-5f1fd7adb6e7",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb6ee894-9afc-517f-b438-5549c20f786a",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.5.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab8c5a3c-22b0-594e-9a75-e05d2d5c86f1",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.5.0.post3+tuxcare"
    }
  ]
}