{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:89585e8f-600d-586b-8a04-82033c5abbbd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/keras@2.15.0.post1+tuxcare",
      "type": "library",
      "name": "keras",
      "version": "2.15.0.post1+tuxcare",
      "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:edd3571c-fefc-52e6-b352-4fce0c54d473",
      "id": "CVE-2024-3660",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3660 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88792db7-f9d6-5b77-91d4-d8f090844f4a",
      "id": "CVE-2024-55459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-55459 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fa05bc-d0af-5384-b574-ada2c2f58c1a",
      "id": "CVE-2025-12058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-12058 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6740360d-ef2c-57c2-87f8-ac512d0d3701",
      "id": "CVE-2025-12060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-12060 is fixed in version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f909d94-7647-5e67-b121-fa31528a07a9",
      "id": "CVE-2025-12638",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-12638 is a false positive for keras 2.15.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75b7f8a6-9f02-5a9f-a61b-10c1f4d787c5",
      "id": "CVE-2025-9906",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-9906 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a24c09-87d6-5fb2-a0af-2c0ecd877267",
      "id": "CVE-2026-0897",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0897 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4258f2a9-0e4b-5858-a18d-ec4d230785bf",
      "id": "CVE-2026-1462",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post1+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462"
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44064fa-690e-5f8c-bc85-a2e75d059559",
      "id": "GHSA-28jp-44vh-q42h",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-28jp-44vh-q42h is a false positive for keras 2.15.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7199b33f-6bcd-55c8-8293-ca021da744db",
      "id": "GHSA-5478-v2w6-c6q7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-5478-v2w6-c6q7 is a false positive for keras 2.15.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
    }
  ]
}