{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:325429c0-066e-5f81-a52d-d4cb5ca60260",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post5+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fc079298-1277-5a0a-8872-3b71527ac14a",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74fd28d-461c-5d0d-be90-0df140ac677d",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5ed9277-1ce6-5bbd-8e29-7db5ebb01ec7",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:302cf14e-e717-54dc-9611-50be45b4fa2f",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f771905c-a478-5c4f-8760-a51bbd2224ae",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b9b0981-e054-5eda-81ee-666df432fc6e",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c24d81b7-3c25-5c47-8085-c3fdf388eabd",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ef5578-43df-5c69-ba7a-be3b4319bf5c",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c9bc1a-8448-54e0-b420-a75160db060b",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68a193fe-9dae-5edd-bb27-0f21ae511c6a",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74eb428b-658b-5129-9d03-b9b104a73461",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd26257-db70-5e7f-bd1b-7482f38aa9b8",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50d3a8e8-0727-5532-b974-21fa476a20ab",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2aeb3dc-85df-5c6d-8f41-7f6c2a4fe89d",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48182c15-3db7-5ed2-a212-af0280ac7147",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76f8f0bc-e832-5001-bbe5-ad419adc7888",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a602df-6477-5c25-a6a8-3a8c9d2f2f88",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06d8ba3-b7d7-5eca-9756-675eaccb2951",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86c05162-af2d-56d3-95b9-b73b6451b373",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post5+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7748f1f0-a2b7-5f74-b03d-b5a2be6c938e",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46435e63-3dc8-5e1a-ba7d-9d268031de2c",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e485362b-d56c-5529-8e1f-d2f36773faa9",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d1ada8f-7448-5186-bed5-b97b896dec71",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
    }
  ]
}