{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6267da75-2630-5817-9ba8-596bc7e9522a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "django",
      "purl": "pkg:pypi/django@5.0.post16+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/django@5.0.post16+tuxcare",
      "version": "5.0.post16+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-24680",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9584aa42-37db-54f6-9d9d-0766bd9b837d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-27351",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8898b441-fdd6-5c78-b77a-caa5e89ad52b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27351 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-38875",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bc82fc38-8d91-5949-aad3-002f14bb7cda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39329",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5a41fb48-d764-55ee-83d3-e83fd99e4a89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39329 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39330",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1b540c2e-adfb-5478-b0ee-a4a27b17af12",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-39614",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9631f996-19a9-5c0c-8926-cf8a4b0fd972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41989",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3d9275cb-2f5d-591e-9bb4-67b287c2f512",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41989 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41990",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4228e76d-3de3-5e63-b786-f4942c25ad69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-41991",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7385ef1d-9242-52bd-bf4e-fd3a24fa7ee2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-42005",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9e531ff3-d8c1-5483-8a09-2c4f4359396a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45230",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5185df5b-c95b-5157-8e1b-a12f4dc3845f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45230 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-45231",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:15de8ffe-0065-5744-975c-25041839d58a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-53907",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fb7fb1fe-c3bf-5a5d-be7d-544a5875fc5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53907 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-53908",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b8ae16ff-9a6e-5761-be0d-2553829760cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53908 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2024-56374",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:dc3d65d2-4984-5c78-9f0d-3e49f209e2d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56374 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13372",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f6240b89-79ba-5d90-ae0e-c5c463876c9f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-13473",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:be6c7ab1-b82e-5daf-bca6-c5930960bb45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-13473 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-14550",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fea8e69e-572e-537e-bcdb-00f38d861c58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-26699",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5e40d208-9144-5ad6-87f1-430e50a139f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26699 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-27556",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:86396557-33e1-5fff-ad6b-2bcb76bd8155",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27556 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-48432",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b0c222a9-9d0d-589d-bc84-272b700ef0e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-57833",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:177600e6-09a6-52c5-8197-137ec162af3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64458",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:44f3fb3e-08a5-510d-a00c-840c5ad8ab1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64459",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e089f890-8688-56b4-b030-367c4877de6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2025-64460",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7a9914fa-a2c6-5ac3-8639-e2af59627ceb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64460 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1207",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3a44ac15-e60b-5bc0-aa2d-64bc3a335410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1207 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1285",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5b1e7eff-5502-54e6-a382-3331560d3991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1287",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:32f95cb5-ec0f-5749-9529-b23c6e93b73a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1287 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-1312",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ffe8083f-8db9-5546-bffc-6aed8fe81c8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1312 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15307",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e3647b77-c4a2-58e3-989e-9f7e3bc755e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-15307 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-15830",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6063ef3c-2b79-5aed-867a-27916c0fbe24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-15830 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48587",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8661f8fc-6d99-54c7-8154-799fa2e512bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48587 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-48588",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:da0a71b9-fc4c-5ba0-924f-c88c57eecba5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48588 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53877",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1f420f26-2bba-5641-abc1-97582cdf489f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53877 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-53878",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e08f1fd6-6ef5-5e34-a58c-0c5108af782c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-53878 does not affect version 5.0.post16+tuxcare of django. not_affected \u2014 Django 5.0 does not contain the vulnerable DomainNameValidator class. This validator was introduced in Django 5.1 (commit 4971a9afe5). Since the specific component affected by CVE-2026-53878 does not exist in this version, Django 5.0 cannot be affected by this vulnerability. Additionally, all domain validators present in Django 5.0 (_simple_domain_name_validator, EmailValidator, URLValidator) a...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-6873",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3e9a8532-a779-5685-a252-303bce20d6cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6873 is fixed in version 5.0.post16+tuxcare of django."
      }
    },
    {
      "id": "CVE-2026-8404",
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post16+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ad2ffe70-201f-5d97-8fb8-25edaf8b3b54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-8404 is fixed in version 5.0.post16+tuxcare of django."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/django@5.0.post16+tuxcare"
    }
  ]
}