{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cec295f6-a85f-5463-8f93-0bce7897ec77",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "django",
      "purl": "pkg:pypi/django@4.0.post22+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/django@4.0.post22+tuxcare",
      "version": "4.0.post22+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-45115",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:37249fb3-89f4-58bb-bacf-ff27c2b3ecfd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2021-45116",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b62a15ae-d29f-5add-95bb-a843fa8f98d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2021-45452",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:42dec791-52cb-5d9f-8fc2-b95942644ca4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-22818",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c1e10d7a-ce74-54b3-becb-566d1fe1cd75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-23833",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fa3bffd0-2e28-59f0-9904-3d398e2770c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-28346",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:03975810-a3e9-59d6-b290-eabc2a8dcd1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-28347",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5cdb146f-aa64-5c13-ac72-8de1a1e3a89d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-34265",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c1685d60-5fc3-594f-8098-2a59ffa1f75a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-36359",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c0beb006-ed26-59ed-98e7-95f24a8664e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2022-41323",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3d30dd6d-bfef-5808-87b8-701634f4b03b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-23969",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c70d837b-3abc-5b33-9166-16de8b07a5f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-24580",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:06304519-db25-5daf-b786-8fd5c8d097ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-31047",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:adb8e5b9-362e-54af-b2f2-81c403f602dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-36053",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b47ebb77-a5fe-5d91-aba8-7cc8649d9efe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-43665",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ad354550-360c-5d3f-a89e-533875cf1030",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2023-46695",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:030221a5-b3a8-5fc2-82c2-77d7016a4c71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46695 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45231",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b76c75bb-256d-5690-a033-259c57d2d916",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13372",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:580f6cba-d9f7-513c-b887-151d1518b4c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13473",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a4a6dd41-f11b-59dd-a46d-b5352c7c2537",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-14550",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a53bcdc8-e40f-5f79-a0a5-3585208e9bce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-48432",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a3b39e38-4f52-535c-8a4c-eb22332c68bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-57833",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:047144c1-4f9c-5315-8527-16573a909933",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64458",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8a1056b9-7a60-5372-92fa-e0b78b5830ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64459",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4b8b9eab-c1e6-554b-a734-6ab1592b3414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64460",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8fbeb865-0898-597f-8c96-8e9d49871a6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1207",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0cdbb057-8081-5299-bc40-aa8c54550cb8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1285",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d2364629-d34b-5d1f-9f0a-b6102ad72064",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1287",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9bebc610-6cfb-536e-aeae-76b904333703",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1312",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:de4dab85-c017-5bf9-9713-602397cbc2d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15307",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b4ebff2e-3d7c-5ebf-bd7b-117ed37047de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15307 affects version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15830",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e47eb130-654c-599e-8971-5a946fff3d58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15830 affects version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48587",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d615bd2a-d616-5bbf-bef1-a49b9f522e1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48587 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48588",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0516c29a-7f6e-59e1-b32e-7acd10d32b75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53877",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ec549636-c7ab-578f-9512-4900cb6221fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53877 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53878",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:10837297-984f-5eae-aefb-7d5d1d10ee97",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.0.post22+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe...",
        "justification": "protected_at_runtime"
      }
    },
    {
      "id": "CVE-2026-6873",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2183afae-d13a-5696-93f4-3097c6a1dd61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6873 is fixed in version 4.0.post22+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-8404",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post22+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1ccb5087-330a-5604-a3b0-a8116c5cbb1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 4.0.post22+tuxcare of django."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.0.post22+tuxcare"
    }
  ]
}