{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:98302bc7-e4ec-57d2-9cf4-d0d5faa5ee48",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "8.4.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:92908f34-a3f3-5717-b60c-046d36bea3a2",
      "id": "CVE-2022-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22815 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:befe2515-6518-5539-b3ff-9242604368b3",
      "id": "CVE-2022-22816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22816 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02fc3747-ffe2-5351-945c-8616f4484286",
      "id": "CVE-2022-22817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cd5989-11f3-5ec4-9b35-caf24120fa41",
      "id": "CVE-2022-24303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24303 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f55e886b-3928-54fc-ad50-4e9a6f3e9698",
      "id": "CVE-2022-45198",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb68f813-e194-5b43-be35-17dbd19e01e9",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44271 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6581a77b-9231-5669-9a45-fcd422fb4b22",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post1+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:910961a1-79ca-5ddf-9ebf-795448781100",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2852f914-56d9-52fa-90da-ac507480d164",
      "id": "CVE-2024-21272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21272 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d293af-f807-5c8a-a710-98e9a79705cc",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b02c4f1b-b447-5b41-8ed2-e20b7b6d9740",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3d8978-8800-57af-8d46-8b8b584df553",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28734b65-d743-5802-98ae-72fd13fdd3e9",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c608551-17cf-5068-86c3-f46b37bec26c",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52673c1d-88ff-55cc-bc6f-441ecff4490b",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1cedf34-9fd7-5e4a-b0ec-f4ee78d3ac49",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c3a2da-5fb4-5d1a-8894-835fbf2009cd",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec649a35-da48-5492-bae2-c2173676023b",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:569b0536-ad84-5b2a-a7b5-9252de43ebe6",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b594be-7817-54c6-9099-079c0ba04d27",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c562f0-f89f-535e-86e4-758e37291dc3",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7567d8-5f2a-595a-b370-d34ee0ad3fab",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e0938b-c880-5915-8c3e-1536ac749250",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4f30ec-b2b2-53e1-9310-faba832d7a39",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e131fa3b-b47d-5e27-855e-49363b960f67",
      "id": "GHSA-4fx9-vc88-q2xc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ad517f-203f-52ae-8f67-ca79e3c964f6",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
    }
  ]
}