{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9ed14dfc-cbef-5208-9cf0-fbbda2dfc908",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.4.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a4c792ec-6a1e-57cf-939c-7b3a581fa754",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3040c843-47d7-5fc0-a9f6-96272195329e",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-4863 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4754a6f-eb5f-5835-83a1-9b24dbf32d44",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-50447 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03741c0c-e16c-5171-8b4f-66e5ba1ea775",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3161a06-95c4-541a-ae9d-0505d795ad86",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d539dc7-912e-5f48-b525-18a92d285178",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf1bcc6-9951-50cc-b62d-d7ae848032a2",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76cb8f9a-e5ce-5102-aaaa-b87e113a7e92",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6525f7ea-d269-526a-9a5e-fa10e8605f61",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c8a012-9869-5d02-a49c-62b114f3d177",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0e47d1-1e14-55f2-8db9-59915490517d",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4400d100-3592-5dd4-837f-976662a741b7",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be1cde53-13b8-5849-a2ff-122ac342cae6",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262ebbd0-b435-58ec-8514-cbe4c9913038",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8826175d-a6f4-52d9-9ab0-15b69eb9f475",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90395ddd-d57a-50e2-b6a8-bec6463c7954",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1b9dec6-df4e-5377-ac84-cb660dc1ff3f",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2c23bb-3c8b-5a85-ae59-967f05eac6a3",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ac173e1-d3ae-5cf1-8695-78090db89cd7",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
    }
  ]
}