{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:255a0d83-096b-5f3c-8dd9-b2964ca141be",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare",
      "version": "11.3.0.post5+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-25990",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4334ca92-c485-5b8a-b6d4-16031407fd5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-40192",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8114a35b-c732-5a62-b2ff-6ec13b0e1255",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b8bcee29-358e-5789-842b-2e35c6470e7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42308 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42309",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:57e987fe-bb9d-5464-a615-f4e6b32129d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:11341214-2655-584e-8f80-e92b8fd3d93e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42311",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d01b2c4d-3aef-5960-b1d6-93c79606ad54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42311 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54058",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fc52013d-cd37-521e-8185-f328e59115a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54059",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:11cca86e-64a5-599e-a773-9576f0ac75f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54059 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9e6993c3-66a9-55e3-9caf-7f64e6712cac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55379",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:deecfdf8-e752-51c7-9907-199f85e501ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55379 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bbb5f793-98b8-5fd4-9ec3-f76102fafb95",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55380 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6712ca00-1e19-5c3f-bf0b-bebbe597f7cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:495ff498-67c7-54e2-8349-56ed85dde045",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59197 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f27f7289-1ff2-5a2d-913a-17ddde386571",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59198 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6d3378ea-32d1-5229-bc61-d2073a7e8dc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4a23e3b3-9cb4-546e-a366-9c42887a2d4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:fb3f1df5-e548-5a82-ab66-4019ed78c1d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59204 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0072d7a5-575e-5068-9449-4bde59fd550f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59205 is fixed in version 11.3.0.post5+tuxcare of pillow."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@11.3.0.post5+tuxcare"
    }
  ]
}