{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4e22d9d9-45a0-5650-8e40-89645f8fd33b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "2.10.1.post2+tuxcare",
      "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e1fb854b-7871-5f9c-8cff-1eb9d28f120f",
      "id": "CVE-2025-45768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:990a5a75-b449-542c-a4c3-08c448548d93",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32597 affects version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e45c5ee1-bbc2-538d-8627-a8c3b9fab7e5",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post2+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5951ca3a-968b-58dc-93f4-58b0b5b2db95",
      "id": "CVE-2026-48523",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d248b02-5006-5ea5-85f9-1c121d707d1d",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae2fec6c-70b2-584f-be82-1e70147db8b2",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04063afd-d45f-520a-9134-9be279f70c0a",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
    }
  ]
}