{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6cd0300a-955e-5233-8e6f-6bb85112df61",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "django",
      "purl": "pkg:pypi/django@4.2.post13+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/django@4.2.post13+tuxcare",
      "version": "4.2.post13+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-13372",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3f8bda75-19b0-5f75-8d08-4f4d6e61efed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13473",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ac78e610-c43b-57f3-8d9c-785d0c4b02b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-14550",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:367fb428-a866-5c6f-8436-3a30c5b0716d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-48432",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:196e7e6d-2d57-5e90-9b3a-cd64c28b1700",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-57833",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b5866346-04e7-54c8-bc40-83697408f68d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-59681",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:61f54ad5-491f-5ee9-bf92-d92b118f3488",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59681 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-59682",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:20df02eb-bed2-5a4e-8ea1-280cafd25ee1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59682 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64458",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a8748e9f-5e98-598a-b6c9-80da59e7825a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64459",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:22c62534-d896-53d3-90c1-ab141f9279c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64460",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6d71a5b7-f444-53d7-9563-65c16deaed02",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1207",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0a482753-c533-5fd8-9aab-336c958320df",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1285",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e85971ea-97a1-502d-a06c-52cc3b9b71b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1285 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1287",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fa3a02c7-639d-5d58-887a-67f87d0f7d11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1312",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8538ad69-4d40-5701-863f-7c65a33748a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15307",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d31b8a75-8fb3-5b12-bd20-dc857b9f3932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15307 affects version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15830",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d77a822e-b9e5-5869-8ff6-f66a3762824f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15830 affects version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-25673",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:03a214b3-afe2-55f8-84ce-5edac9fadf41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25673 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-25674",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5148f680-d6ca-5aa2-b779-d62653fe0cf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25674 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-33033",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a005f5e1-fe58-576d-802b-0184e9bda85d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33033 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-33034",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4dc8e4f9-2b65-5793-b48e-e903c2e9425c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33034 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-3902",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c0c6d7c6-a9e9-5fab-b722-dafc67c2cd07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-3902 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-4277",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f9cfc9df-7038-593b-bbd4-52f56b86c840",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4277 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-4292",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4758596b-4729-57d3-87ca-0924056c20b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4292 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48587",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:93358e2c-dac9-52a3-b48a-aee87a9ac1fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48587 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48588",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1f710898-4932-5591-b3fc-c01b8d6069d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53877",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3598dd22-195e-5be3-84fd-2f572c5b36d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53877 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53878",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0e55717c-c7c6-512f-9beb-2c7eb139dee2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 4.2.post13+tuxcare of django. not_affected \u2014 Django 4.2.0 is not affected by CVE-2026-53878. The vulnerable component `DomainNameValidator` does not exist in this version (it was introduced in Django 5.1). All existing domain validation mechanisms in Django 4.2.0 already prohibit newlines: URLValidator explicitly checks for newlines in `unsafe_chars`, EmailValidator uses regex that doesn't match newlines, and _simple_domain_name_validator...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-6873",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:366754bc-93fb-50e9-a346-0109f9fecf59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6873 is fixed in version 4.2.post13+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-8404",
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5243b966-21ae-506c-977a-cf8bc0a710d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 4.2.post13+tuxcare of django."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@4.2.post13+tuxcare"
    }
  ]
}