{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:674f359c-1a45-55fd-a590-4d31683bc5e8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "10.4.0.post3+tuxcare",
      "purl": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9b74d560-f4db-5553-8072-4cd770dfbe07",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c77d169-299a-5a19-8bf9-0e372dde6f25",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3b795a-016d-5b35-9cea-40608928fb18",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8d5f531-3989-5e4e-8888-9ab6ab954d5a",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a9b34c-7aa8-5486-a912-554a2dc49c06",
      "id": "CVE-2026-42311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42311 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad37220d-7b61-55cd-beb5-a2cf4a39b9f9",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4cd0bba-13be-5268-ba81-82757071f0da",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5469d074-d99d-5b70-8a9d-93110ed91a82",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17a2dcdf-7e8a-5e0e-94dd-547b6e128e00",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41799d37-63e2-5121-b856-79bf594481af",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55c8bf59-e63e-597d-88d1-a3226d89b97d",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1184022-7343-5f9f-a231-25f9777412b7",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06baa39d-1f56-59a6-96c2-3265190d46bc",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a676fa18-9118-5763-af75-f6ffe360fac9",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec60bc0-0e73-5f66-be8d-89ee42252586",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b3f2448-e84b-572d-975e-6db619424821",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b30483f-2352-57f9-b1ba-7e63c54dd47a",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 10.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@10.4.0.post3+tuxcare"
    }
  ]
}