{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e3ce7ddf-344a-5439-984d-71473360a94f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.4.post4+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:db937299-9ba5-5e3e-a354-99562d6d7c9a",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528a879d-604c-5d13-8766-60d09c5b4924",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b00635a8-3f8f-5c1c-ab8b-c2922ce6c937",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a4557de-6fe0-5923-85bf-8781a0a94c6b",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff42c389-95a0-5e98-8926-822725592e2b",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d87ec456-17d8-5d00-92f2-9aad80b70d60",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6f68ea-5e63-5f2e-9a11-b9c017ee297d",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b44b4e8-87bc-5250-9189-942ae9e9d8e2",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b934ef-db93-5ff3-ad9d-777055ef957f",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
    }
  ]
}