{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4cd8f4c5-63f2-5135-90a0-d5ebfdd5b658",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare",
      "version": "9.4.0.post8+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-44271",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a3b312ef-c92f-5548-90b0-f9d2c962380a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2db33e64-1514-54f1-8605-3cb25d183da9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7a023249-ec5b-5478-aec7-dc5f98c80bfb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d9035a69-f557-5707-801a-0dc51ebd95b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:02559b00-3ac0-573e-a7c5-4f661348bc25",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1aecc7d9-d15e-5761-8e48-d44cb4022e5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54058",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7759f848-8782-5f29-bea3-f4e12ded7ecc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:778cfc1f-1cf6-5af8-a6b9-a3de291598ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:046bcb54-ca3e-5712-ad87-17d0bed2b8a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7e39d8e0-c8a3-5ca8-bfea-61143db7569b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0d3b9f5d-6b0c-52c5-91b9-57417d18f75a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59197 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b7d3832f-eabe-5461-bf0c-3884ad9efc14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1fd34cff-b053-5321-9dd1-00e0c1ab2b30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:77f6dd5f-a575-55b7-a885-4366f0947116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:78d39901-c2a5-5c31-9de9-6601dcd3ac7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post8+tuxcare of pillow, and is fixed in 9.4.0.post9+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:89003196-fba8-5cd9-9ae5-15cbbb250d33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59205 is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f0ed45ee-c0ec-5e7c-9d09-c5cf0aa0c5e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post8+tuxcare of pillow."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.4.0.post8+tuxcare"
    }
  ]
}