{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9ed3763b-8632-54d0-b0f0-471540e2a3f1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare",
      "version": "9.5.0.post6+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-44271",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6f472d62-6415-5efa-90ff-71a650108673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d62cfad1-35a6-5786-8183-6a2fb4787a41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ce281152-de51-5c11-b370-a3f4ff411010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4bd0c4e5-ebad-5f0e-b2f8-4c081363e92b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:daf37f38-586a-5291-b0cc-f7021e7a1133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4c4bec9f-1d6c-50fe-a1bd-291fbebedd0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54058",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2be42159-b280-5c38-9a1d-fcda1f4d8dd8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ec90e443-f280-500e-8f9d-a7e7761d2154",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7c8b8e7d-11b6-50d1-bf47-51b6d97a89ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f2ccf4ad-a249-542f-9665-5a77a8863edc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a6b05784-3b88-5d8c-8838-8080652e2bd8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e7f4c199-a8d7-59de-b20a-4cb000dbe653",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bc5456d6-46d7-524a-846c-0317330f3959",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4215558d-cedb-50ac-bb21-52e4b6717d42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 9.5.0.post6+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2e03400e-4a17-59d2-909c-bea3e49fb4e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9ec84de2-32c2-5506-83b7-a4c653ece018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.5.0.post6+tuxcare of pillow, and is fixed in 9.5.0.post7+tuxcare."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c06f8d23-3ac3-5c79-82cb-d82eaaeac10b",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post6+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.5.0.post6+tuxcare"
    }
  ]
}