{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0c4e5b68-c677-58cb-9efa-67bf355c1092",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/django@4.0.post9+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post9+tuxcare",
      "purl": "pkg:pypi/django@4.0.post9+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e3701459-8c7a-50e5-a025-29352a92814a",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4248e626-dbd3-5cdf-b727-6d2c1115e03d",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c90a5242-c60d-5581-accc-0b25ce037a10",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4874d73-27da-52ae-a8dc-0edbe17e606f",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d60b30e9-7684-59a4-a749-af91484abc12",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0f9ae4-5905-564a-ab46-fbcffa9c825a",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf7e441-29c1-5edb-a6c3-ac36cc6027d7",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c25a3e7e-fedc-553b-aeb2-3a22ae24775e",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f66941-235e-593b-87e6-1748070fa6b8",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02d366e2-eb4f-59c4-8067-caa24835e882",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8698f383-0ed4-5365-ae3a-56151135ee89",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e77aab83-9c29-5406-966d-0c62b5a0b917",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7406a09f-93bd-5eaf-920e-0ceff74fe51e",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-31047 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7813e6d7-ef9e-5559-81f1-e78398b646b2",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36053 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca15dee6-fef1-56c3-8c9f-6390aa0a4c24",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43d942ab-f617-5b3a-be62-a5df72117e51",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c2db21d-f778-542c-990f-06365bf4c0a3",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0958fea-fb62-576f-a085-c1567faab1f7",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0456252c-3640-5457-84ce-e42cfd9b9994",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b28d6f2-be3c-511d-b47b-a25622eeebbb",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac3246f3-64f7-59e8-a062-7e11076ed16b",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f54d4c-a033-5e86-a4f1-b382de00b677",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e84976cb-39a1-5756-b90d-1f61e4b3f787",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92ad6e8e-ec7d-5088-ab89-e0f62185c48a",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f47d4311-83d9-51ce-8e63-acdb94351e64",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a1b02e-0254-5830-a922-e8af1be2ba40",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79288e7a-b77f-59ac-bcf3-12d43064b537",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:339da72c-4652-5ad4-af3f-8addc9dba4bc",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:918ab70f-3656-545c-a76a-6bc288d28b07",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3433e1fb-5bed-5b4b-ba07-a9f0b8b66daf",
      "id": "CVE-2026-48587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48587 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4eb38a1-a7b4-5663-ae7f-47800964c7b6",
      "id": "CVE-2026-48588",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48588 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21939d6d-697e-5531-8be9-5001d0acf23c",
      "id": "CVE-2026-53877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53877 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64b73aff-e37f-502f-aef8-6262b846f96e",
      "id": "CVE-2026-53878",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.0.post9+tuxcare of django. not_affected \u2014 Django 4.0 is not affected by CVE-2026-53878. The vulnerable component DomainNameValidator does not exist in this version (it was introduced in Django 5.1). All domain validation in Django 4.0 is performed by EmailValidator, URLValidator, and _simple_domain_name_validator, which properly reject domain names containing newline characters through various mechanisms (regex anchors, explicit unsafe..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb3d62e8-cd9f-57b9-8175-d4164f7537fe",
      "id": "CVE-2026-6873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6873 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5893c934-5189-55bd-a374-9cde341a9680",
      "id": "CVE-2026-8404",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-8404 affects version 4.0.post9+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post9+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.0.post9+tuxcare"
    }
  ]
}