{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3ff743fb-4970-5b3d-98ea-c2ddbc4ef650",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare",
      "version": "8.4.0.post8+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-22815",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:89746234-1743-5756-a93c-50442442f3f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22815 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-22816",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e7b7c1b7-bc57-5bac-ae8d-7aaf4a87de16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22816 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-22817",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:13aafdc9-d721-5c2f-b097-20ebdd4aebdc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2022-45198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2d8596af-12ca-55ab-8afc-06c1d80b9866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c7ab1021-def8-5df3-a2a1-694c79d08070",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post8+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:04d464ba-4c6e-5d40-80ca-92e4e4c5919c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:20a936ad-9907-5346-b05d-181da5f41529",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c6dcad36-b528-5bdc-b053-2bdafaba258a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42308 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:eb0c4312-37f2-52e0-8677-514e47b65369",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4f34ef67-5260-5a88-ac28-3c90e9312d01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:dc6ec675-c0b4-55f9-a423-9778d3a58e15",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55380 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f2c7aa6e-368f-53c5-8fb7-d3c38e5506fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d264f9a9-05ba-5e0c-9f8d-5c6179ad80cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59197 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:26666074-b000-5f62-b3d0-1943adf2a4e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59198 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:af5c0086-f3e9-5cae-9a07-e0d1330bc4af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:86c26983-56bb-50a9-b1af-af2037ffe79b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cf97e851-1199-5be4-a1d0-f617301674b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59204 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:77fa4ec2-ac9f-58e3-a606-205dcbdbc914",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59205 is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-4fx9-vc88-q2xc",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:16a1f10a-e7fb-525e-aee0-71ad269806af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc is fixed in version 8.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:85d25b16-a1ec-5afc-89e6-b48f4f6424cf",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post8+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@8.4.0.post8+tuxcare"
    }
  ]
}