{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:17443819-80f8-5fa5-b2f1-00e1e3e0c131",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "pillow",
      "purl": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare",
      "version": "9.5.0.post7+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-44271",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4f52d2b5-3450-5281-b8c0-3e16a9f87f11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-4863",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bbd60caa-a04a-56a2-b775-eeb7cb0eff3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2023-50447",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:976e62ad-5590-573a-ba90-aa84e0a2bf83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2024-28219",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:19517c2f-5ad6-5471-88b9-8fb742cb142a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-42308",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e143837d-4111-5cf7-b4b0-dd6f2d561869",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-42310",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9ca369d3-de82-5722-b33b-b34222f2b886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42310 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54058",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5abf588a-cff1-5d81-be62-9c618f34bef6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54058 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-54060",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:04852e9a-f033-5d60-a224-8e3f64d257a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54060 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-55380",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:626fa0d8-770e-5cdf-bac7-1b5e6424132f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-55798",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3a2e06f1-7f27-5473-a251-418720d99b47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55798 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59197",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6dc040f5-4bc9-5c4d-bd4a-0df3341f8042",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59197 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59198",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:653ce561-5ee1-5a29-9f7f-8b1a2d436500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59199",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cead8370-0f64-58e6-bc5e-090c82f77e40",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59199 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59200",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8fc87cd4-37d4-5ac4-9c7b-bbfa8611cc8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59200 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "CVE-2026-59204",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:48bddf05-8818-5ed2-a105-3bf3a7cfebb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post7+tuxcare of pillow, and is fixed in 9.5.0.post8+tuxcare."
      }
    },
    {
      "id": "CVE-2026-59205",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:63509f88-91d1-5992-ba10-1ef1f2af2b24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59205 is fixed in version 9.5.0.post7+tuxcare of pillow."
      }
    },
    {
      "id": "GHSA-56pw-mpj4-fxww",
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bda0df80-25f2-513c-8813-f6232671d59e",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post7+tuxcare."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/pillow@9.5.0.post7+tuxcare"
    }
  ]
}