{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:78aa6c3a-72bb-5f32-82ab-e7a826a5106f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "django",
      "purl": "pkg:pypi/django@5.0.2.post10+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/django@5.0.2.post10+tuxcare",
      "version": "5.0.2.post10+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-27351",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cf5faf8f-e253-5f84-85e2-398cda9df503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-38875",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ac548313-268a-5ac1-a5bd-545d7a18494f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39329",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a5265f6d-34a2-5961-bc7b-042c4e754a6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39330",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:62cfeca9-56a5-54bd-bd8e-4ce1ed7f93a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39614",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:770edf6d-ba81-5062-84e4-79847fe4b9e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41989",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cee2c45b-967b-56f0-897a-5c95c23d1831",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41990",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:456b0b87-7de2-59d0-a754-d4fa16ec2d1b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post10+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-41991",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3559b098-1bba-54a9-bdf5-bac9ee08eb05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-42005",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4378ec01-9594-5cce-bb56-a2ada0677efb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45230",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:663f2784-20a9-5ac2-9e83-37392bb7c2ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45231",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:abb2ab22-8d93-5a10-968d-89ad21034367",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-53907",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:129f6fac-ea07-5b29-9fa7-4da09334a38f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-53908",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9c4f9b50-ee51-550a-978e-c89b175ed8a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-56374",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:90f064fb-3e77-53c3-9f2b-4da11f5e94c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13372",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:668924ad-2718-5670-8635-06ea746c9247",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13372 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13473",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a6f8eb84-c853-5a15-bc14-b9e1c8e0832a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-14550",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7a754669-9109-5b12-bd65-009898ce1dbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14550 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-26699",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bb9f41f4-599b-5dad-85db-640f5776dca8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-27556",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e042c187-d97d-557b-beda-8bdc36042c18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-48432",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:18f71eec-0f0c-55df-97cb-3370bbc6bb2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-57833",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:be43dfa8-466b-5213-8f07-a54bc0665f09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64458",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4b3412bc-b493-57f1-81a0-476405a1ab2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64459",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b444d097-8ce8-5b89-9fb4-cdf7488acb25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64460",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d60b372c-dd0c-50d7-815c-fa101fd83cc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1207",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d08965ea-f78b-528e-a08f-88269b05efa7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1285",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:177d28b9-e8e7-524a-9334-62e5de875b55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1287",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b2fa6cdf-136e-5d65-8188-ac506de7ebf0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1312",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8963f888-b56c-5e5b-8f1e-a64c40581fde",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15307",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:952e745f-0358-5004-a20d-bc36afe08b1e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15307 affects version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15830",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:aef900ff-bd61-5aa0-871d-844d171a01c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-15830 affects version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48587",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9ff5df71-27d8-5559-8e75-488bbed50df3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48588",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:65d46b09-0619-5993-8637-5242b6a74f76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53877",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e0a17e61-f62a-5645-99c8-a5edeca24e40",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53878",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3a29dec3-92d1-58b3-bb77-a7c0e593f40e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post10+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-6873",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8f64b36f-245b-5837-b2e5-33f8ecd6cca5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-8404",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7d3182e0-64bc-547d-ba72-475eb70b0625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post10+tuxcare of django."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.0.2.post10+tuxcare"
    }
  ]
}