{
  "@id": "urn:uuid:85ee9027-8d26-476f-9547-3495f2fa1deb",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 2,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-01T04:50:02.038518+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-27351"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-38875 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-38875"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39329 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39329"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39330 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39330"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-39614 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-39614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41989 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41989"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post10+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-41990"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-41991 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-41991"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-42005 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-42005"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-45230 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45230"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-45231 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-45231"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-53907 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53907"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-53908 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-53908"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2024-56374 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2024-56374"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-13372 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13372"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-13473 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-13473"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-14550 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-14550"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-26699 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-26699"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-27556 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-27556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-48432 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-48432"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:50:02.038518+00:00",
      "status_notes": "Vulnerability CVE-2025-57833 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-57833"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64458 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64458"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64459 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64459"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2025-64460 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2025-64460"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1207 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1207"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1285 affects version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1285"
      },
      "action_statement": "Vulnerability CVE-2026-1285 affects version 5.0.2.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1287 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1287"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-1312 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-1312"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-15307 affects version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15307"
      },
      "action_statement": "Vulnerability CVE-2026-15307 affects version 5.0.2.post10+tuxcare of django."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-15830 affects version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-15830"
      },
      "action_statement": "Vulnerability CVE-2026-15830 affects version 5.0.2.post10+tuxcare of django."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-48587 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48587"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-48588 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-48588"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-53877 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-53877"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-53878 does not affect version 5.0.2.post10+tuxcare of django. not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-53878"
      },
      "impact_statement": "not_affected \u2014 Django 5.0.2 is not affected by CVE-2026-53878. The vulnerable code (DomainNameValidator class) does not exist in this version - it was introduced in Django 5.1. Django 5.0.2 uses _simple_domain_name_validator which already validates against newlines via string.whitespace."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-6873 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-6873"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/django@5.0.2.post10+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/django@5.0.2.post10+tuxcare"
          }
        }
      ],
      "timestamp": "2026-10-01T04:49:00.278202+00:00",
      "status_notes": "Vulnerability CVE-2026-8404 is fixed in version 5.0.2.post10+tuxcare of django.",
      "vulnerability": {
        "name": "CVE-2026-8404"
      }
    }
  ]
}
