{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f2a6e24a-5224-5a2c-bf5f-43f54239d81d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.4.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:457628e9-076f-5a6b-b439-e545e0628dae",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b8564f-3b2a-56f9-8dec-8d38732fd6c8",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c739d734-2537-5112-88c3-f190d61cfbc1",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f135a81c-68d2-534e-9bdb-76390bde877c",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e45fe5-657f-59a7-8177-1241be513a6b",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e561dd2f-771c-53b6-8491-80f37f08467b",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bc1723-752b-5884-a7f2-f958cc96c935",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec76b1d-08cb-5c62-af5c-d0804bf8ec71",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ca93ef-47d4-59e7-b795-d5bad2b11b8e",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63eb3397-4fe9-5922-b5f9-fe6100da553f",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba23351-b56d-5506-bced-6924afe613df",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95799179-7e09-593e-9d76-7951829c2eb8",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:970825fb-426a-5edc-9026-40e750716185",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1afbe32-6b56-5b88-bfa3-a464ba1d9d26",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa93dba5-ea57-5ec0-ab46-847a29cdb049",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61992c96-36fa-5cab-9751-e8ee541e3a9c",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d59174-90b8-56f4-b90f-754d02a7a954",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:510b87c4-9cd0-5a3d-ac2d-527e12960335",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0c626b-af93-5608-ac16-592df494d8c0",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
    }
  ]
}