{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ad968c2a-23b3-5136-83cb-217b8e4bdb0d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.4.0.post3+tuxcare",
      "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6c8a7fd6-3061-53f6-9b6a-dc339469b792",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:695e1bd8-da63-578c-b759-75cc63984378",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0862a20b-99cc-5fb6-9a8c-3831be4d2dd4",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d18547-37cc-50a2-9276-a088f65cba93",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ed2fdf-1e10-5374-b2ec-64fd933dc289",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf73ff11-8703-5470-85af-f4f0016b9510",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f05bba2-4379-5c88-b604-97d8b8a71342",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5c1a0b-38be-5057-a423-834752254f95",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ca487d-07cc-53a4-aa65-14dad569f62c",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6307da06-9668-5e0f-a79e-afe4999fa122",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b386795-cca2-5c07-a0d3-f189830f1f3f",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f9b8740-cff0-5784-8f6a-ebf9fb70d1c4",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f30aefa0-71ce-5a96-b440-5523b7a217ca",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfab8405-65e8-5bbf-ab7f-342588cc6994",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a9ecbbb-ddc3-56e7-9618-acc9a57e8cf4",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc6d0f8b-4515-5629-8d79-53011dc99b75",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7478569e-0e66-5bf1-ae34-7f1bd2f496dd",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fec0d205-3505-5889-aae0-571fce6c765d",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d88ae911-ff68-5885-9c87-7b26aaaceed3",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
    }
  ]
}