{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:26782390-c203-5253-af3e-9fc2027140f9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.5.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a834fe01-f00e-5bcd-80ec-d7ef4abdebea",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44271 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcbaca3-982d-5225-abc2-0ba967fa73c8",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b591eab9-6796-539b-b3d8-63f7b09144dd",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96b7d033-74fb-5829-adf1-362e20162f48",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c192be02-ba2d-5026-9d60-109834c58e06",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4dab50-c600-5926-a83d-38529dc6314e",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4dbddb1-4ff4-5813-a04e-1a7241462ec0",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0523441-4c4a-5ed0-b9fd-5287a42236aa",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc016222-2f92-543e-bb4d-ff029689afbf",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:154f6b7d-0316-5d4f-b2b6-36393c7ba513",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3a1e1f-b23c-5335-a935-3a5af0b97a2b",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad08abe-51e4-5a0c-b1f7-b9f137379b2f",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:627654be-8b23-5c35-9fb5-29d197bd6e65",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b1caf1-ae6c-580e-86a2-6124b5d840e8",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b37ad3da-1970-52a3-932d-8d76db4a192a",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c59056e-83d8-5c3e-a9ca-ec1b17220c31",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9e2f7e5-8310-54c7-a698-13fda00ee333",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20b0ddcf-b2de-5064-bb49-c377d1e6ac82",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4f9886-dac6-56ad-8e86-caeed51897ae",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
    }
  ]
}