{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9e128604-7b5a-5dac-9458-dba2ee459c01",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "keras",
      "purl": "pkg:pypi/keras@2.15.0.post3+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/keras@2.15.0.post3+tuxcare",
      "version": "2.15.0.post3+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2024-3660",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8910df1a-0fa2-5568-85df-3ceebc533bef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3660 is fixed in version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2024-55459",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bc635b9f-3964-51e4-9b4c-bef17a8165ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-55459 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2025-12058",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1d770566-8b10-5b21-80fa-719dd784308c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-12058 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2025-12060",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cea870f6-5f95-5f0f-9501-cdf5321a235a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-12060 is fixed in version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2025-12638",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f1843920-8b4e-58a2-b999-27d521bac1f5",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-12638 is a false positive for keras 2.15.0.post3+tuxcare."
      }
    },
    {
      "id": "CVE-2025-9906",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:edf3cd4a-0561-54c0-9fa5-98c648e5eeed",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-9906 does not affect version 2.15.0.post3+tuxcare of keras. keras 2.15.0: vulnerable API (keras.config.enable_unsafe_deserialization / KerasSaveable, keras 3.0-3.10) absent in 2.x; malicious .keras gadget fails with TypeError. esultanaliev 2026-10-02",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-0897",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:869b71c6-75fc-5e66-8dae-5624d38df207",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0897 does not affect version 2.15.0.post3+tuxcare of keras. keras 2.15.0: fix is in KerasFileEditor (keras/src/saving/file_editor.py), module absent in 2.x. esultanaliev 2026-10-02",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-11816",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:75383df4-3a2f-5599-b4c5-d88b89c8f8ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-11816 is fixed in version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2026-12479",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:12b635db-862b-5fc2-b31b-c264771ffd3a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12479 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2026-12480",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1042d913-52bd-528a-b5a6-518a3d43b201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12480 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2026-12481",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ef2d39ea-eb35-56c0-92a4-70f4e53a02f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-12481 is fixed in version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2026-12482",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:41bad9ac-f4a1-5797-8bd6-5d4f5669b504",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12482 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2026-12484",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:68c6aecf-d4d4-50b0-8c4b-35ca656901df",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-12484 does not affect version 2.15.0.post3+tuxcare of keras. keras 2.15.0: TorchModuleWrapper absent in 2.x (TF-only). esultanaliev 2026-10-02",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-12570",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:72c2ac24-8a67-5486-9e57-141b05be0dac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-12570 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "CVE-2026-1462",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bbb764da-94de-54b0-b0cb-4173733a77ee",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post3+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-9335",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:05400fe8-d15b-5ce4-90cf-bd097324cb04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-9335 affects version 2.15.0.post3+tuxcare of keras."
      }
    },
    {
      "id": "GHSA-28jp-44vh-q42h",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8451bf41-1a43-56ca-af00-5a098a26d7d9",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-28jp-44vh-q42h is a false positive for keras 2.15.0.post3+tuxcare."
      }
    },
    {
      "id": "GHSA-5478-v2w6-c6q7",
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8bc315c5-8091-56a0-904b-ce219bcfc481",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-5478-v2w6-c6q7 is a false positive for keras 2.15.0.post3+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/keras@2.15.0.post3+tuxcare"
    }
  ]
}