{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:940317b6-5274-531f-aba0-d4a8a5fd69bc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post4+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f8b79dba-c38f-5f55-a544-d1566652cbb7",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:067a8e82-5878-5a18-a002-333114f92dae",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4f77041-3469-59e1-8d95-40dcc7088924",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post4+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5145c7e7-8d2b-53e4-9a91-3cf64a8a12eb",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58bfd745-50ef-56a8-8829-dab729cf040a",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c320cda8-8209-5a9a-ae34-59406495e1df",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5928e03e-0ee2-5be9-8c6f-a8c1f181b3fb",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb51ad8-9b8b-575c-8a0e-a812fe845b04",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49e5300-ceb6-5eb5-b5ba-592a7a0b833a",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
    }
  ]
}