{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:abbc4eb6-3707-5c56-8328-ccdac58d8624",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post4+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cce123dc-cec4-563d-a75e-bfa4df0b9372",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dced148-7ed1-5d0b-9b39-b806a8c6a968",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa8c2ca4-5e9e-5bc8-b16f-2882364f373f",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d192b8-9dd1-55bf-968b-39d5eda3f846",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c127a6d-e266-58fd-a1be-3fb057dfe723",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9e3ef7-1951-54cf-8829-4aff1418ecc2",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c85462-f73f-5942-a979-6f63ce66e2ee",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c5255fb-429f-588f-b8e6-2329365b2645",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c920e343-dd6d-5162-ae04-83d8a8039dc2",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0111da5b-c1f5-5c1f-831c-85b85d42b85c",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19b053c-9c4a-5096-98d2-b9c3372a1fdb",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8af589-4d70-51bd-9ece-955a059c480c",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b354f1fd-03ae-58dc-a523-46c7090f253f",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a928aa-a73d-5b17-a7f1-94e6aeebe174",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a1a6fb3-e9f9-5db7-bf63-81772d189e30",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230b4d4b-f06a-5b0a-ab4b-3de2f742249d",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1d72ae-55fd-5574-9c69-8e59da417f47",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ab1c242-3dfd-5f73-ac17-ba132ff83689",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52105181-8b10-5b55-b032-faf36b474868",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0af7b9b-3f0a-5cb3-93a5-5047483a38aa",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddfcc83-4e72-5173-b33b-05173a1fa956",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71af69ca-1bde-5265-92f4-189175ada235",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794af869-4405-5d32-be9a-52bdcfba3c08",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f9057c2-70eb-5f25-a981-4949fe5a20c8",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15620ce5-e9a3-5e13-89c8-719212996b8e",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08693af5-e419-5f54-a2f3-f70eb74ce26f",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba315a4-2973-5a35-8fc1-9ade448a626c",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b0d557e-51ee-53f4-9c4a-3960c525db4a",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48c63b84-518f-5d51-9f38-8a1fb7967947",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93002daa-f7f6-5c58-b483-9b82c160527d",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f169968-6d44-5878-bccd-0fc0d2ab125c",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:278e0323-3087-5562-8742-1c289df144b9",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e20f3af5-d3d6-5d20-82a6-3053ae6fe6ac",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7afd15a-1fdf-53dc-b2ee-4e62af30af44",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:490d180f-1beb-57fe-8de6-0673e86488d2",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16b351c1-8738-5113-a2d9-d92015f150f1",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a040e3e9-8e64-5150-ab29-a66955e64b70",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46bc5ff9-1a20-598b-a7eb-7ab24dc8e563",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c240ff19-da5f-57c2-8ce5-4d5af52bc461",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e4ecda-ac68-5b91-997d-b33e1cd8ecb5",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
    }
  ]
}