{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7af6054-819b-53ef-8c89-12c86e9c2eee",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "tornado",
      "purl": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare",
      "version": "5.1.1.post4+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-28370",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:db662a7c-c55e-5d0c-aa88-81e750cd845a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28370 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2024-52804",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8972467d-b5cb-5a13-9fe4-49a80fed25bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2025-47287",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:decddc3c-91fa-5f70-8d0d-88d0945fcd3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2025-67724",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:912f9ed5-bb98-52ca-ae4f-cc08d3ceadb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67724 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2025-67725",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9685c950-1e38-5abb-b575-4263afbf7f61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67725 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2025-67726",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a231c94b-ad25-50bc-8dfb-57229ad34b44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67726 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2026-31958",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7fa8b131-eddc-53b5-aa16-b89915654f4c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31958 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2026-35536",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ea68b901-1361-5d7b-921a-0ee77e7ba7f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-35536 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2026-49853",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cb6fc2ec-14d1-5ac5-91b9-08f1fb32d5fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49853 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2026-49854",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:800d0357-29fb-57e7-850d-38d8ece562c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49854 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2026-49855",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b2ee9d97-7615-5539-874b-c5ca5f38a539",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49855 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "CVE-2026-82397",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:58cdb3df-c3bc-5606-a546-e8e864bbe3f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-82397 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "GHSA-3hv7-mjh2-fv65",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b9ec372f-9537-5270-9abb-e52835d0e183",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3hv7-mjh2-fv65 affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
      }
    },
    {
      "id": "GHSA-753j-mpmx-qq6g",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e85d3398-4199-5b1d-9e44-005ee5079bd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "GHSA-78cv-mqj4-43f7",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7cef018a-8994-5365-b577-19aa21913786",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "GHSA-8423-8fgw-73vq",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:516b9695-ee6a-5ee4-9941-9282aa817b90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-8423-8fgw-73vq is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "GHSA-c2m8-h5v5-343r",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2129f48c-9be2-5164-8b4e-207ce565be7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-c2m8-h5v5-343r affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post5+tuxcare."
      }
    },
    {
      "id": "GHSA-chx6-46f5-w4vp",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:56eeca41-cca5-51b5-9839-3387692849a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-chx6-46f5-w4vp affects version 5.1.1.post4+tuxcare of tornado, and is fixed in 5.1.1.post6+tuxcare."
      }
    },
    {
      "id": "GHSA-pw6j-qg29-8w7f",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3c5898a4-5ec6-5987-a2fc-e7ebbb705cb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "GHSA-qppv-j76h-2rpx",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f36e8985-e3e2-5f7a-8fe3-517b6b82a059",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    },
    {
      "id": "GHSA-w235-7p84-xx57",
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9baf64af-a549-5f39-9478-dbdfd1d16123",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 5.1.1.post4+tuxcare of tornado."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/tornado@5.1.1.post4+tuxcare"
    }
  ]
}