{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:094a9e8f-726f-5a14-b23e-abb04b1b6963",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare",
      "version": "10.4.0.post9+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-25990",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cbb68fb8-57b5-5e23-8910-a982ea2b0764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-40192",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b36e7acf-f90b-5766-bbaa-581b82d99d6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f6e2a11a-d1b4-599e-a42d-464ed9f6e61c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1eb325b6-19f2-5219-be70-e689462e7fd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42311",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6ccabfed-a136-5f9e-8afd-0d8da1d16954",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42311 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54058",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:abb0a729-1bf1-53ac-9005-efb264479f44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54059",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0c29c9c9-8993-559a-92f9-b72abb8fe3ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54059 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:85553e66-5f1a-5e4e-8474-ef953ef5027e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55379",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:91a0326c-2cce-53ac-ba17-a315ea45befc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55379 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4811ceaa-7eb1-59ce-8268-f9fa362a7240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:93b9fd5d-0510-5592-957d-fe7ff82abff4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:67d9d444-f71d-5df7-80a2-5d233c1456b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59197 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:83bbe532-4349-5103-b404-54dfc2d42c2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d0753636-a252-5558-9d59-5de0b9107967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ba5472df-1a31-5eb8-9933-6c6ded3cbef1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:12d537b8-ca3c-5f30-9298-fc90cdb8b329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 10.4.0.post9+tuxcare of pillow, and is fixed in 10.4.0.post10+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:535edfad-bc53-5c8c-863d-9211b4229a72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59205 is fixed in version 10.4.0.post9+tuxcare of pillow."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@10.4.0.post9+tuxcare"
    }
  ]
}