{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ae696ec3-f0c7-5a13-a8a8-c79709e56d7f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "6.1.0.post1+tuxcare",
      "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:db05dccc-b31b-54c9-9dcc-7d6974a336fc",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-28370 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ba4bd3-f043-54b9-9a92-6409d10aef7b",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb478015-02cc-5daa-b2f1-813373cbfd01",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77d3943e-c449-5d25-9233-07111af67f5b",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67724 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc3bd027-a303-5caa-8786-fc95bce8c55b",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67725 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473cdc79-ef3b-58ef-93e0-fc222ec238f3",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31958 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c50ee4a-ca7d-576a-8341-94a463ea5832",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-35536 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2914ab-2da6-5202-9337-b1e510d8b527",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49853 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2532ecc-2f3d-570e-8362-1e134ab7a70f",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49854 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66af16e3-fe44-5fcb-9bdb-b1b204e5ad3a",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49855 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8215998-1211-50b3-b46e-b1d45c8ac773",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29273111-564b-5a58-bad8-84566f9f59d4",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2cbb63-09d1-5c8c-b91a-a2ad3276ef15",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:446fe487-6f6c-5a50-9ac4-868158b5f2f1",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99109be-a0e2-54b1-b6ab-0cf985e370c2",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
    }
  ]
}