{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d5c7d55a-e350-54a5-bea5-dc15649d44f7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "10.4.0.post4+tuxcare",
      "purl": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b9060aa9-76df-57de-9103-602ba05c1f80",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f474ae8e-7934-562c-bbb0-2c17a9c93bb3",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44e00944-6ae6-5e45-8485-d6ced207a300",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6366217-3b07-5ab2-8363-234764520394",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f6c0ad4-73e8-5ac2-936e-22b89a6c28e8",
      "id": "CVE-2026-42311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42311 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5794cb11-a569-520e-9700-d6bb9cc79308",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9d2ba40-a337-5527-9fa3-3151ae6a6e05",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10a53603-5917-5427-aa10-112f8628eb10",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7bf70b3-dde4-52cc-9613-0558713dfa4f",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af22f151-320d-506b-a103-aa22809da0ab",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d14b34-4d98-5e9e-a74d-1667b80c22e0",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec335129-9f64-5ea4-aad1-58c3483b9c04",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2953bd08-d286-5edb-8546-53486f67dbd2",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff26573-1a87-56a0-97e0-43e0cec1c1bd",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c6a1b12-45e4-5673-9bd5-34cb9247fe54",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea18bf72-697d-5e7c-9098-951febceba35",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc6db3e4-c859-572f-beb6-e94d68542963",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 10.4.0.post4+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@10.4.0.post4+tuxcare"
    }
  ]
}